Customer Key support for Microsoft Teams now Generally Available!

Published 05-13-2021 08:00 AM 13K Views

Service encryption with Microsoft 365 Customer Key
Microsoft 365 provides baseline, volume-level encryption enabled through BitLocker and Distributed Key Manager (DKM) which ensures customer data is always encrypted at rest in the Microsoft 365 service with BitLocker and DKM. Microsoft 365 offers an added layer of encryption at the application layer for content, including data from Exchange Online, SharePoint Online, OneDrive, and Teams, called service encryption.


Microsoft 365 Customer Key is built on service encryption, providing a layer of encryption at the application layer for data-at-rest and allows the organization to provide and control the encryption keys used to encrypt customer data in Microsoft’s datacenters. Customer Key provides an additional protection against viewing of data by unauthorized systems or personnel, complimenting BitLocker disk encrypted in Microsoft datacenters. Customer Key enhances the ability of organizations to meet the demands of compliance requirements that specify key arrangements with the cloud service provider, assisting customers in meeting regulatory or compliance obligations for controlling root keys.

Microsoft 365 Customer Key now supports Microsoft Teams!
After providing the keys, Microsoft 365 then uses the provided keys to encrypt data at rest as described in the Online Services Terms (OST). The organization can create a data encryption policy (DEP) and assign it to encrypt certain Microsoft 365 data for all tenant users. While multiple DEPs can be created per tenant, only one DEP can be assigned at a time. For customers already using Customer Key for Exchange Online and SharePoint online, data encryption policies add broader control and now includes support for Microsoft Teams! Once a DEP is created and assigned, it will encrypt the following data for all tenant users:

  • Teams chat messages (1:1 chats, group chats, meeting chats and channel conversations)
  • Teams media messages (images, code snippets, video messages, audio messages, wiki images)
  • Teams call and meeting recordings stored in Teams storage
  • Teams chat notifications, Teams chat suggestions by Cortana, Teams status messages
  • User and signal information for Exchange Online
  • Exchange Online mailboxes that aren't already encrypted using mailbox level DEPs
  • Microsoft Information Protection exact data match (EDM) data – (data file schemas, rule packages, and the salts used to hash the sensitive data)

When a DEP is assigned, encryption begins automatically but will take some time to complete depending on size of the tenant. For Microsoft Information Protection and Teams, Customer Key DEP encrypts new data from the time of DEP assignment. We are working to bring support to encrypting past data. For Exchange Online, the DEP starts encrypting all existing and new data.
For more details on using Microsoft 365 Customer Key across multiple workloads and how to get started, please see Service encryption with Customer Key.

3 Comments
Senior Member

Very welcome addition :) Teams team (no pun intended ;-D) is so awesome!!!

New Contributor

Question:  If we already make use of a policy assigned to all mailboxes, which as we understand includes Teams information, what does this recently announced functionality provide?  Does it cover Teams data not exclusively stored in the mailbox?  Thanks for your efforts re. data encryption.  The other announcement about E2E is well received!

Microsoft

@ctd-dc correct, it covers more Teams data than was previously available thru Customer Key for Exchange, SharePoint + OneDrive. Thanks for the positive feedback!

%3CLINGO-SUB%20id%3D%22lingo-sub-2349855%22%20slang%3D%22en-US%22%3ECustomer%20Key%20support%20for%20Microsoft%20Teams%20now%20Generally%20Available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2349855%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3EService%20encryption%20with%20Microsoft%20365%20Customer%20Key%3C%2FSTRONG%3E%3CBR%20%2F%3EMicrosoft%20365%20provides%20baseline%2C%20volume-level%20encryption%20enabled%20through%20BitLocker%20and%20Distributed%20Key%20Manager%20(DKM)%20which%20ensures%20customer%20data%20is%20always%20encrypted%20at%20rest%20in%20the%20Microsoft%20365%20service%20with%20BitLocker%20and%20DKM.%20Microsoft%20365%20offers%20an%20added%20layer%20of%20encryption%20at%20the%20application%20layer%20for%20content%2C%20including%20data%20from%20Exchange%20Online%2C%20SharePoint%20Online%2C%20OneDrive%2C%20and%20Teams%2C%20called%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fcompliance%2Foffice-365-service-encryption%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Eservice%20encryption%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EMicrosoft%20365%20Customer%20Key%20is%20built%20on%20service%20encryption%2C%20providing%20a%20layer%20of%20encryption%20at%20the%20application%20layer%20for%20data-at-rest%20and%20allows%20the%20organization%20to%20provide%20and%20control%20the%20encryption%20keys%20used%20to%20encrypt%20customer%20data%20in%20Microsoft%E2%80%99s%20datacenters.%20Customer%20Key%20provides%20an%20additional%20protection%20against%20viewing%20of%20data%20by%20unauthorized%20systems%20or%20personnel%2C%20complimenting%20BitLocker%20disk%20encrypted%20in%20Microsoft%20datacenters.%20Customer%20Key%20enhances%20the%20ability%20of%20organizations%20to%20meet%20the%20demands%20of%20compliance%20requirements%20that%20specify%20key%20arrangements%20with%20the%20cloud%20service%20provider%2C%20assisting%20customers%20in%20meeting%20regulatory%20or%20compliance%20obligations%20for%20controlling%20root%20keys.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSTRONG%3EMicrosoft%20365%20Customer%20Key%20now%20supports%20Microsoft%20Teams!%3C%2FSTRONG%3E%3CBR%20%2F%3EAfter%20providing%20the%20keys%2C%20Microsoft%20365%20then%20uses%20the%20provided%20keys%20to%20encrypt%20data%20at%20rest%20as%20described%20in%20the%20Online%20Services%20Terms%20(OST).%20The%20organization%20can%20create%20a%20data%20encryption%20policy%20(DEP)%20and%20assign%20it%20to%20encrypt%20certain%20Microsoft%20365%20data%20for%20all%20tenant%20users.%20While%20multiple%20DEPs%20can%20be%20created%20per%20tenant%2C%20only%20one%20DEP%20can%20be%20assigned%20at%20a%20time.%20For%20customers%20already%20using%20Customer%20Key%20for%20Exchange%20Online%20and%20SharePoint%20online%2C%20data%20encryption%20policies%20add%20broader%20control%20and%20now%20includes%20support%20for%20Microsoft%20Teams!%20Once%20a%20DEP%20is%20created%20and%20assigned%2C%20it%20will%20encrypt%20the%20following%20data%20for%20all%20tenant%20users%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ETeams%20chat%20messages%20(1%3A1%20chats%2C%20group%20chats%2C%20meeting%20chats%20and%20channel%20conversations)%3C%2FLI%3E%0A%3CLI%3ETeams%20media%20messages%20(images%2C%20code%20snippets%2C%20video%20messages%2C%20audio%20messages%2C%20wiki%20images)%3C%2FLI%3E%0A%3CLI%3ETeams%20call%20and%20meeting%20recordings%20stored%20in%20Teams%20storage%3C%2FLI%3E%0A%3CLI%3ETeams%20chat%20notifications%2C%20Teams%20chat%20suggestions%20by%20Cortana%2C%20Teams%20status%20messages%3C%2FLI%3E%0A%3CLI%3EUser%20and%20signal%20information%20for%20Exchange%20Online%3C%2FLI%3E%0A%3CLI%3EExchange%20Online%20mailboxes%20that%20aren't%20already%20encrypted%20using%20mailbox%20level%20DEPs%3C%2FLI%3E%0A%3CLI%3EMicrosoft%20Information%20Protection%20exact%20data%20match%20(EDM)%20data%20%E2%80%93%20(data%20file%20schemas%2C%20rule%20packages%2C%20and%20the%20salts%20used%20to%20hash%20the%20sensitive%20data)%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EWhen%20a%20DEP%20is%20assigned%2C%20encryption%20begins%20automatically%20but%20will%20take%20some%20time%20to%20complete%20depending%20on%20size%20of%20the%20tenant.%20For%20Microsoft%20Information%20Protection%20and%20Teams%2C%20Customer%20Key%20DEP%20encrypts%20new%20data%20from%20the%20time%20of%20DEP%20assignment.%20We%20are%20working%20to%20bring%20support%20to%20encrypting%20past%20data.%20For%20Exchange%20Online%2C%20the%20DEP%20starts%20encrypting%20all%20existing%20and%20new%20data.%3CBR%20%2F%3EFor%20more%20details%20on%20using%20Microsoft%20365%20Customer%20Key%20across%20multiple%20workloads%20and%20how%20to%20get%20started%2C%20please%20see%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fcompliance%2Fcustomer-key-overview%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EService%20encryption%20with%20Customer%20Key%3C%2FA%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2349855%22%20slang%3D%22en-US%22%3E%3CP%3EMicrosoft%20365%20provides%20baseline%2C%20volume-level%20encryption%20enabled%20through%20BitLocker%20and%20Distributed%20Key%20Manager%20(DKM)%20which%20ensures%20customer%20data%20is%20always%20encrypted%20at%20rest%20in%20the%20Microsoft%20365%20service%20with%20BitLocker%20and%20DKM.%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22SUR21_Laptop4_Contextual_001_RGB.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F280364i45DA6B1A986F27DC%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22SUR21_Laptop4_Contextual_001_RGB.png%22%20alt%3D%22SUR21_Laptop4_Contextual_001_RGB.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2349855%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2360019%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20Key%20support%20for%20Microsoft%20Teams%20now%20Generally%20Available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2360019%22%20slang%3D%22en-US%22%3E%3CP%3EVery%20welcome%20addition%20%3A)%3C%2Fimg%3E%20Teams%20team%20(no%20pun%20intended%20%3B-D)%20is%20so%20awesome!!!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2414607%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20Key%20support%20for%20Microsoft%20Teams%20now%20Generally%20Available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2414607%22%20slang%3D%22en-US%22%3E%3CP%3EQuestion%3A%26nbsp%3B%20If%20we%20already%20make%20use%20of%20a%20policy%20assigned%20to%20all%20mailboxes%2C%20which%20as%20we%20understand%20includes%20Teams%20information%2C%20what%20does%20this%20recently%20announced%20functionality%20provide%3F%26nbsp%3B%20Does%20it%20cover%20Teams%20data%20not%20exclusively%20stored%20in%20the%20mailbox%3F%26nbsp%3B%20Thanks%20for%20your%20efforts%20re.%20data%20encryption.%26nbsp%3B%20The%20other%20announcement%20about%20E2E%20is%20well%20received!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2446521%22%20slang%3D%22en-US%22%3ERe%3A%20Customer%20Key%20support%20for%20Microsoft%20Teams%20now%20Generally%20Available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2446521%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F621651%22%20target%3D%22_blank%22%3E%40ctd-dc%3C%2FA%3E%26nbsp%3Bcorrect%2C%20it%20covers%20more%20Teams%20data%20than%20was%20previously%20available%20thru%20Customer%20Key%20for%20Exchange%2C%20SharePoint%20%2B%20OneDrive.%20Thanks%20for%20the%20positive%20feedback!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎May 12 2021 03:10 PM
Updated by: