Review customer-managed keys for Azure Storage

Choose encryption keys that meet organizational key-management requirements.

Description

Azure Storage encrypts data with Microsoft-managed keys by default. Customer-managed keys are an option when an organization needs direct control over key permissions and rotation.

Potential impact

A diagnostic-log account using only Microsoft-managed keys may not meet requirements for separate organizational key control.

Remediation

When required, configure either the customer_managed_key block or a separate azurerm_storage_account_customer_managed_key resource. Set up managed-identity key permissions and key recovery and rotation procedures.

Examples

These excerpts associate a separate key resource. Configure diagnostic categories and identity/key permissions separately; apply ignore_changes to the account’s customer_managed_key to avoid conflicting management.

Before

hcl
resource "azurerm_storage_account" "logs" {
  name                     = "examplediagnosticlogs"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name               = "subscription-diagnostics"
  target_resource_id = data.azurerm_subscription.current.id
  storage_account_id = azurerm_storage_account.logs.id
}

After

hcl
resource "azurerm_storage_account" "logs" {
  name                     = "examplediagnosticlogs"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  identity {
    type         = "UserAssigned"
    identity_ids = [azurerm_user_assigned_identity.storage.id]
  }
}

resource "azurerm_storage_account_customer_managed_key" "logs" {
  storage_account_id         = azurerm_storage_account.logs.id
  key_vault_key_id           = azurerm_key_vault_key.storage.id
  user_assigned_identity_id  = azurerm_user_assigned_identity.storage.id
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name               = "subscription-diagnostics"
  target_resource_id = data.azurerm_subscription.current.id
  storage_account_id = azurerm_storage_account.logs.id
}

References