Skip to content

Keyvault

Azure Key Vault

Zone Failover / HA

Keyvaults are not configured within zones, but are configured per region.

Regional Failover / HA

Keyvaults are provisioned per region. If multiple region availability is required, Keyvaults should be mirrored across regions, but this is a manual, end-user function and not an Azure native feature.

Encryption at Rest

Yes - standard tier is via software (platform managed) key.
Premium tier is HSM protected.

Encryption in Transit

Yes - TLS and PFS.

Compliance and Security Controls