Creating a CMEK for Azure | Teradata VantageCloud Lake - Azure: Creating a Customer Managed Encryption Key - Teradata Vantage

Teradata® VantageCloud Lake

Deployment
VantageCloud
Edition
Lake
Product
Teradata Vantage
Published
January 2023
ft:locale
en-US
ft:lastEdition
2024-12-11
dita:mapPath
phg1621910019905.ditamap
dita:ditavalPath
pny1626732985837.ditaval
dita:id
phg1621910019905

This capability is in Limited Availability for interested customers. Contact your account team if you are interested in using CMEK in VantageCloud Lake on Azure.

Customer managed encryption keys (CMEK) allow you to control encryption keys to protect your organization's data. You choose the rotation schedule and the granularity of access.

  1. Create a single-region encryption key in Azure Key Vault that is created for the same region where your Teradata environment is hosted. Teradata recommends creating a new key to use to encrypt your environment.
    Important: The new key is essentially blank, do not assign any other Azure accounts or roles. This is done when you start provisioning the environment.
  2. Obtain the URL for the key, for example https://keyvault.azure.com/something/else/goes/here.
  3. Follow the instructions in Step 1: Signing On and Creating Your First Environment to create the Environment; then return here.
  4. Complete within 14 Days after Creating the Environment

  5. Copy the App ID from the VantageCloud Lake Console and use it to allow the App in your Azure vault access to the managed encryption key.
    Screenshot showing App ID and how to copy it.
  6. Select Complete Setup to secure the environment with your CMEK that you manage in Azure KMS.