Remediation
From Azure Portalβ
- Go to
Monitor. - Select
Activity log. - Select
Export Activity Logs. - Select a
Subscription. - Note the name of the
Storage Accountfor the diagnostic setting. - Navigate to
Storage accounts. - Click on the storage account.
- Under
Security + networking, clickEncryption. - Next to
Encryption type, selectCustomer-managed keys. - Complete the steps to configure a customer-managed key for encryption of the storage account.
From Azure CLIβ
az storage account update --name <name of the storage account> --resource-group <resource group for a storage account> --encryption-key-source=Microsoft.Keyvault --encryption-key-vault <Key Vault URI> --encryption-key-name <KeyName> --encryption-key-version <Key Version>
From PowerShellβ
Set-AzStorageAccount -ResourceGroupName <resource group name> -Name <storage account name> -KeyvaultEncryption -KeyVaultUri <key vault URI> -KeyName <key name>