Remediation
From Azure Portalβ
- Go to
Monitor. - Select
Activity log. - Select
Export Activity Logs. - Select a
Subscription. - Note the name of the
Storage Accountfor the diagnostic setting. - Navigate to
Storage accounts. - Click on the storage account.
- Under
Security + networking, clickEncryption. - Next to
Encryption type, selectCustomer-managed keys. - Complete the steps to configure a customer-managed key for encryption of the storage account.
From Azure CLIβ
az storage account update \
--name {{storage-account-name}} \
--resource-group {{resource-group-name}} \
--encryption-key-source=Microsoft.Keyvault \
--encryption-key-vault {{key-vault-uri}} \
--encryption-key-name {{key-name}} \
--encryption-key-version {{key-version}}
From PowerShellβ
Set-AzStorageAccount `
-ResourceGroupName {{resource-group-name}} `
-Name {{storage-account-name}} `
-KeyvaultEncryption `
-KeyVaultUri {{key-vault-uri}} `
-KeyName {{key-name}}