Skip to main content
protectGetKey / Decryptvault APIenforceAccess policyZero Trust · RBAC + ABACMicrosoft 365Office / Purview clientLayer 1Azure RMSMicrosoft keyLayer 2DKE Cockpityour organization keyVault / HSMRSA key — never exported
Content is protected by two keys — Microsoft’s (Layer 1) and yours (Layer 2). On decrypt, Office calls the DKE service, which enforces the access policy before unwrapping with the vault-held key.
Applies to:
DuoKey Cockpit v2Microsoft 365 / PurviewDKE 365
Screenshots being refreshed

Some pages in the wider DKE guide still show screenshots of an older console. The behaviour documented in this section reflects the current Cockpit; refreshed screenshots are being rolled out progressively.

How to: DKE for Microsoft 365 — end-to-end walkthrough

What changed for DKE 365 in Cockpit v2​

DKE (Double Key Encryption) protects Microsoft 365 / Purview content with two keys: one held by Microsoft (Azure) and one held by your organization. Cockpit v2 hosts the organization-side RSA key and serves the Microsoft-compatible GetKey and Decrypt operations — now with a redesigned configuration model.

Highlights of the v2 DKE implementation:

Clean management surface

A streamlined management surface to deploy, enable, rotate and monitor DKE services, plus the public protocol endpoints that Office calls directly.

Rotation with overlap

Key-rotation with an overlap window — the previous key keeps serving GetKey and Decrypt during a configurable cache window so no content becomes temporarily unreadable.

Azure AD provisioning

Automatic Azure AD app provisioning via Microsoft Graph on enable.

B2B partner domains

B2B partner-domain support (each allowed domain maps to its own tenant's valid token issuers).

Access-policy engine

A policy engine (RBAC + ABAC) for access control (user / IP / location / time / group) — see Access Policies.

A running DKE service — health, key algorithm and rotation
A running DKE service — health, key algorithm and rotation

Platform (recap)​

Cockpit v2 is the next-generation rewrite of the DuoKey platform. Security highlights that apply to DKE: strong authentication (JWT + WebAuthn), a policy engine (RBAC + ABAC) for authorization, AES-256-GCM encryption at rest, and a tamper-evident, hash-chained audit trail with fail-closed guarantees for security-relevant events. Cockpit v2 is multi-tenant, with each tenant's data isolated automatically.

Keys are held in the tenant vault — DuoKey KMS (software MPC by default) plus HSM backends including Securosys (FIPS 140-2 Level 3 & 4). The DKE private key never leaves the vault.

Full platform overview

The same Cockpit v2 platform powers every DuoKey integration. For a broader platform overview, see Oracle TDE → Overview — the platform description there applies to DKE 365 as well.

DKE 365 on the Cockpit — at a glance​

DimensionDuoKey Cockpit
Key algorithmRSA-OAEP-256 (default) or RS256
Key rotationOverlap window (cache_duration_hours, default 24)
Decrypt authAzure AD JWT + optional mTLS (reverse-proxy) + access-policy enforcement
Access controlPolicy engine — RBAC + ABAC (user / IP / location / time / group)
Performance figures

Any throughput, latency or footprint figures quoted for Cockpit v2 are vendor targets, not independently benchmarked guarantees.

What's in this section​