Review customer-managed key coverage for Azure Databricks

Configure CMKs for the data covered by key-management requirements.

Description

Azure Databricks has separate customer-managed key features for managed disks, managed services, and DBFS root. CMKs provide organizational key control; their absence does not imply plaintext storage.

Potential impact

Missing CMK coverage for required data can leave organizational key-management requirements unmet.

Remediation

Identify the data and compute type to protect, then configure the applicable CMK feature. Verify Key Vault permissions, rotation, and recovery procedures.

Examples

These excerpts associate a managed-disk key for classic compute. customer_managed_key_enabled enables the managed-storage identity; these two fields alone do not complete CMK configuration for all data.

Before

hcl
resource "azurerm_databricks_workspace" "example" {
  name                = "my-databricks-workspace"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  sku                 = "premium"

  customer_managed_key_enabled = true
}

After

hcl
resource "azurerm_databricks_workspace" "example" {
  name                = "my-databricks-workspace"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  sku                 = "premium"

  customer_managed_key_enabled      = true
  managed_disk_cmk_key_vault_key_id = azurerm_key_vault_key.cmk.id
}

References