Description
Azure Databricks has separate customer-managed key features for managed disks, managed services, and DBFS root. CMKs provide organizational key control; their absence does not imply plaintext storage.
Potential impact
Missing CMK coverage for required data can leave organizational key-management requirements unmet.
Remediation
Identify the data and compute type to protect, then configure the applicable CMK feature. Verify Key Vault permissions, rotation, and recovery procedures.
Examples
These excerpts associate a managed-disk key for classic compute. customer_managed_key_enabled enables the managed-storage identity; these two fields alone do not complete CMK configuration for all data.
Before
hcl
resource "azurerm_databricks_workspace" "example" {
name = "my-databricks-workspace"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
sku = "premium"
customer_managed_key_enabled = true
}
After
hcl
resource "azurerm_databricks_workspace" "example" {
name = "my-databricks-workspace"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
sku = "premium"
customer_managed_key_enabled = true
managed_disk_cmk_key_vault_key_id = azurerm_key_vault_key.cmk.id
}