Customer-managed encryption keys for Azure Native Service
Elastic Cloud Hosted deployments created through the Azure Native Service are full-featured deployments that support the same security capabilities as any other Elastic Cloud Hosted deployment.
By default, Elastic already encrypts your deployment data and snapshots at rest. You can reinforce this mechanism by providing your own encryption key, also known as Bring Your Own Key (BYOK). For a full description of how this works and the security benefits it provides, refer to Use a customer-managed encryption key.
BYOK is not available as a configuration option when creating a deployment from the Azure portal. You can add a customer-managed key to your deployment after it is created, by accessing the Elastic Cloud console.
Before configuring BYOK, you need an RSA key in Azure Key Vault and the necessary permissions to create a service principal for Elastic Cloud in your Azure tenant. Refer to BYOK prerequisites for the full list.
- In the Azure portal, navigate to your deployment's overview page.
- Select the Advanced Settings link to open the Elastic Cloud console.
- Follow the steps in Encrypt an existing deployment with your key.