Description
Azure Storage encrypts data with Microsoft-managed keys by default. Customer-managed keys are an option when an organization needs direct control over key permissions and rotation.
Potential impact
A diagnostic-log account using only Microsoft-managed keys may not meet requirements for separate organizational key control.
Remediation
When required, configure either the customer_managed_key block or a separate azurerm_storage_account_customer_managed_key resource. Set up managed-identity key permissions and key recovery and rotation procedures.
Examples
These excerpts associate a separate key resource. Configure diagnostic categories and identity/key permissions separately; apply ignore_changes to the account’s customer_managed_key to avoid conflicting management.
Before
resource "azurerm_storage_account" "logs" {
name = "examplediagnosticlogs"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "subscription-diagnostics"
target_resource_id = data.azurerm_subscription.current.id
storage_account_id = azurerm_storage_account.logs.id
}
After
resource "azurerm_storage_account" "logs" {
name = "examplediagnosticlogs"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
identity {
type = "UserAssigned"
identity_ids = [azurerm_user_assigned_identity.storage.id]
}
}
resource "azurerm_storage_account_customer_managed_key" "logs" {
storage_account_id = azurerm_storage_account.logs.id
key_vault_key_id = azurerm_key_vault_key.storage.id
user_assigned_identity_id = azurerm_user_assigned_identity.storage.id
}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "subscription-diagnostics"
target_resource_id = data.azurerm_subscription.current.id
storage_account_id = azurerm_storage_account.logs.id
}