Skip to main content

Frequently Asked Questions

Applies to:
Microsoft 365 E5Azure Information ProtectionDuoKey DKE Service

Licensing and Requirements​

Double Key Encryption for Microsoft 365 comes with Microsoft 365 E5. If you don't have a Microsoft 365 E5 license, you can sign up for a trial.

For more information, see Microsoft 365 licensing guidance for security & compliance.

Additional Requirements

  • Azure Information Protection: DKE works with sensitivity labels and requires Azure Information Protection
  • Microsoft Office Apps for enterprise: See version requirements below for each platform
  • Adobe Acrobat: Pro, Standard, or Reader for PDF protection

Technical Comparison​

FeatureDKEHYOK
Number of KeysTwo keys (your key + Microsoft Azure key)One key only
Key LocationYour key in your control + Azure keyAlways on-premises
Cloud StorageEncrypted data can move to cloudContent stays on-premises
FlexibilityCloud and on-premises optionsOn-premises only

Key Difference: DKE encrypts your data with two keys - your encryption key remains in your control while the second key is stored in Microsoft Azure, allowing you to move encrypted data to the cloud. HYOK only uses one key that must stay on-premises.

Sharing and Collaboration​

Yes, you can share DKE-encrypted documents with users on a separate tenant as long as those users:

  • Have the required permission to access your key in your DKE service
  • Have the required permission to access your DKE service in Microsoft Azure
  • Can access the DKE service URL (e.g., https://dke.contoso.com)
  • The DKE URL is based on a DNS domain registered in your Azure AD tenant

Example B2B Scenario

  • Contoso shares a DKE document with Fabrikam
  • Both organizations must be able to access https://dke.contoso.com
  • The domain contoso.com must be registered in Contoso's Azure AD tenant
Note

If you plan to use https://dke.contoso.com for the DKE service, the DNS domain contoso.com needs to be registered in your tenant. See Microsoft documentation for registering a custom domain.

Deployment and Environment​

Yes, DKE services can run on Azure cloud or any public cloud. With DuoKey's innovative MPC (Multi-Party Computation) key services, you don't need to worry about where the DKE services run, as all private keys reside in highly secure MPC nodes or HSMs.

Security Notes

  • No sensitive material is stored at the DKE Service or DuoKey Cockpit
  • SSL inspection threat is considered LOW due to per-document content keys
  • Keys are protected by MPC and never exist in complete form, so an intercepted key share is useless

Regional and Language Support​

Label Management​

Key Management​

Azure Key Rotation

For rolling the key stored in Azure, see Operations for your Azure Information Protection tenant key.

DuoKey Service Keys

When you create a new key in DuoKey:

  1. Set up a name and GUID for the key
  2. To rotate, keep the old record with its name and GUID
  3. Add a new record with the same name but different GUID
  4. Set the new key as "Active"
  5. The public key API returns the new key for encryption
  6. Both keys remain available for decryption
Tip
Key Rotation Strategy:
  • Create a new DKE label with new keys
  • Keep the old DKE label active until document migration is complete
  • Both old and new documents remain accessible during transition
  • Note: Label changes require human interaction (no automated script support yet)

Email Encryption​

File Support and Bulk Operations​

DuoKey-Specific Questions​

DuoKey enhances the security model by adding an additional encryption layer with the unique capability of managing the keys outside of Microsoft's environment, giving enterprises greater control over their data.

Access Control and Monitoring​

Need More Help?​

Technical Support

Contact DuoKey Support

Sales Inquiries

Contact Sales

Schedule Demo

Book 30-minute demo

Documentation

DKE Setup Guide