Remediation
From Azure Portalβ
- Go to
Monitor
. - Select
Activity log
. - Select
Export Activity Logs
. - Select a
Subscription
. - Note the name of the
Storage Account
for the diagnostic setting. - Navigate to
Storage accounts
. - Click on the storage account.
- Under
Security + networking
, clickEncryption
. - Next to
Encryption type
, selectCustomer-managed keys
. - Complete the steps to configure a customer-managed key for encryption of the storage account.
From Azure CLIβ
az storage account update --name <name of the storage account> --resource-group <resource group for a storage account> --encryption-key-source=Microsoft.Keyvault --encryption-key-vault <Key Vault URI> --encryption-key-name <KeyName> --encryption-key-version <Key Version>
From PowerShellβ
Set-AzStorageAccount -ResourceGroupName <resource group name> -Name <storage account name> -KeyvaultEncryption -KeyVaultUri <key vault URI> -KeyName <key name>