Frequently Asked Questions
Frequently Asked Questions
Common questions about Double Key Encryption during demos and pre-sales discussions
Licensing and Requirements
Double Key Encryption for Microsoft 365 comes with Microsoft 365 E5. If you don't have a Microsoft 365 E5 license, you can sign up for a trial.
For more information, see Microsoft 365 licensing guidance for security & compliance.
Additional Requirements
- Azure Information Protection: DKE works with sensitivity labels and requires Azure Information Protection
- Microsoft Office Apps for enterprise: See version requirements below for each platform
- Adobe Acrobat: Pro, Standard, or Reader for PDF protection
Technical Comparison
| Feature | DKE | HYOK |
|---|---|---|
| Number of Keys | Two keys (your key + Microsoft Azure key) | One key only |
| Key Location | Your key in your control + Azure key | Always on-premises |
| Cloud Storage | Encrypted data can move to cloud | Content stays on-premises |
| Flexibility | Cloud and on-premises options | On-premises only |
Key Difference: DKE encrypts your data with two keys - your encryption key remains in your control while the second key is stored in Microsoft Azure, allowing you to move encrypted data to the cloud. HYOK only uses one key that must stay on-premises.
Sharing and Collaboration
Yes, you can share DKE-encrypted documents with users on a separate tenant as long as those users:
- Have the required permission to access your key in your DKE service
- Have the required permission to access your DKE service in Microsoft Azure
- Can access the DKE service URL (e.g.,
https://dke.contoso.com) - The DKE URL is based on a DNS domain registered in your Azure AD tenant
Example B2B Scenario
- Contoso shares a DKE document with Fabrikam
- Both organizations must be able to access
https://dke.contoso.com - The domain
contoso.commust be registered in Contoso's Azure AD tenant
If you plan to use https://dke.contoso.com for the DKE service, the DNS domain contoso.com needs to be registered in your tenant. See Microsoft documentation for registering a custom domain.
Deployment and Environment
Yes, DKE services can run on Azure cloud or any public cloud. With DuoKey's innovative MPC (Multi-Party Computation) key services, you don't need to worry about where the DKE services run, as all private keys reside in highly secure MPC nodes or HSMs.
Security Notes
- No sensitive material is stored at the DKE Service or DuoKey Cockpit
- SSL inspection threat is considered LOW due to per-document content keys
- Keys are protected by MPC and never exist in complete form, so an intercepted key share is useless
Regional and Language Support
Label Management
Key Management
Azure Key Rotation
For rolling the key stored in Azure, see Operations for your Azure Information Protection tenant key.
DuoKey Service Keys
When you create a new key in DuoKey:
- Set up a name and GUID for the key
- To rotate, keep the old record with its name and GUID
- Add a new record with the same name but different GUID
- Set the new key as "Active"
- The public key API returns the new key for encryption
- Both keys remain available for decryption
- Create a new DKE label with new keys
- Keep the old DKE label active until document migration is complete
- Both old and new documents remain accessible during transition
- Note: Label changes require human interaction (no automated script support yet)
Email Encryption
File Support and Bulk Operations
DuoKey-Specific Questions
DuoKey enhances the security model by adding an additional encryption layer with the unique capability of managing the keys outside of Microsoft's environment, giving enterprises greater control over their data.