See below for the Azure requirements for Vault BYOK.
Supported Azure environments
Vault supports only the Azure public cloud. The following Azure environments are not supported:
- Azure China
- Azure Germany
- Azure Government
Azure account requirements
See below for the Azure account requirements for Vault BYOK.
- Use only one service principal per Azure account; however, you can use multiple subscriptions in the same Azure tenant with the same service principal.
- Do not share the Azure BYOK service principal credentials.
- Do not enable Purge Protection on Key Vaults.
- Do not connect more than one Cryptographic Security Platform Vault cluster to the same Azure account.
Azure endpoint access requirements
If your organization restricts outbound access to the public internet, whitelist the following endpoints for Azure BYOK to work correctly.
https://login.microsoftonline.comhttps://management.azure.comhttps://azure.netWhitelist this endpoint individually for each key vault you want to use.
https://<keyvault>.vault.azure.netWhitelist this endpoint individually for each managed HSM you want to use.
https://<managedhsm>.managedhsm.azure.netIf a proxy is in use in the network, you can test these endpoints in the Vault application on the Settings > Proxy Settings Vault page.