Microsoft Defender for Cloud Apps
Cloud and workloads

Ems Cloud App Security Govt Service Byok

In brief

The page now clarifies that enabling customer-managed data encryption is available only in the Microsoft Defender portal, updates screenshot descriptions, labels the disabling-encryption note as a warning, and improves the key-rotation section heading and anchor.

What Defender admins need to know

Administrators get clearer guidance when configuring or managing customer-managed encryption. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

    | Key Management Operations | - List |
    | Cryptographic Operations | - Wrap key<br />- Unwrap key |

    ![Screenshot of Key Vault access policy with List, Wrap key, and Unwrap key permissions selected for Defender for Cloud Apps.](media/cloud-app-security-byok/byok-kv-access-policy-key-perms.PNG)

2. Under **Select principal**, choose **Microsoft Defender for Cloud Apps - BYOK** or **Microsoft Cloud App Security - BYOK**.


1. Copy the **Key Identifier** URI. You'll need it later.

![Screenshot of Azure Key Vault key settings page with Wrap key and Unwrap key permitted operations enabled.](media/cloud-app-security-byok/byok-kv-key-perms.PNG)
  1. Optionally, if using a firewall for a selected network, configure the following firewall settings to give Defender for Cloud Apps access to the specified key, and then click Save:

    1. Make sure no virtual networks are selected.
  2. Once the URI validation has completed, select Enable.

Handle key rotation

Whenever you create new versions of the key configured for data encryption, Defender for Cloud Apps automatically rolls to the latest version of the key.