Customer-managed encryption keys for VM disks

Customer Managed Encryption Keys (CMEK) for VM disks offers customers control over their data security to manage their encryption keys independently, ensuring compliance with strict security policies and regulations while mitigating risks associated with third-party data breaches. This allows customers to gain full control of their encryption lifecycle, reducing dependency on platform-managed keys. This autonomy ensures their data remains inaccessible to unauthorized parties, even in the event of platform-level vulnerabilities. IT administrators benefit from greater flexibility and security alignment with internal policies.

Add an encryption key

  1. From the Citrix DaaS Flex dashboard, navigate to Cloud subscriptions.
  2. Select the relevant resubscription, go to Customer-managed encryption keys tab.
  3. Click Add key.

    Customer-managed encryption keys-add key

  4. Enter details, and click Add.

    Customer-managed encryption keys-add key-enter-details

Once the key is added, it can be used later when importing images from Azure.

Delete an encryption key

  1. From the Citrix DaaS Flex dashboard, navigate to Cloud subscriptions.
  2. Select the relevant resubscription, go to Customer-managed encryption keys tab.
  3. Locate the key that needs to be deleted from the existing keys table and then from the ellipsis menu, select Delete key.

Rotate an encryption key

If a key’s rotation time has expired, the dashboard displays warning message.

Customer-managed encryption keys-add key-enter-details

Customer-managed encryption keys-add key-enter-details

To rotate an encryption key:

  1. From the Flex dashboard, navigate to Cloud Subscriptions > Customer-managed encryption keys tab.
  2. Locate the key that needs rotation from the existing keys table, and then from the ellipsis menu, select Rotate key.
Customer-managed encryption keys for VM disks