3 ms·
Actually, you can do that already in M365 with Double Key Encryption [1]. The obvious trade-off though is that none of the cloud services will be able to work w
by karmeliet 5y ago
Actually, you can do that already in M365 with Double Key Encryption [1]. The obvious trade-off though is that none of the cloud services will be able to work with your data. For example you won't be able to search or open the document inside the browser which basically renders your SaaS environment (partially) just a plain cloud storage.
DKE should not be confused with any other BYOK service, where you only manage the key, but host it on Azure so MS still has access to you private key.
I think there could be middle ground where customers could select a set of metadata that they are willing to share with the cloud provider or even better, select only the sensitive parts of the document that must be encrypted with their own key.
[1] https://docs.microsoft.com/en-us/microsoft-365/compliance/double-key-encryption?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/compliance/do...