Skip to main content

DuoKey DKE Knowledge Base

Applies to:
DuoKey CockpitDKE Web ServiceMicrosoft 365

Capabilities​

The DuoKey Cockpit enables you to manage the lifecycle of keys and use them to perform cryptographic operations.

CapabilityDescription
DKE Web ServiceSetup and manage DKE services
RBACRole-based access control
AuthenticationMulti-factor and identity provider setup
StatisticsPerformance and usage analytics
AuditComprehensive audit trails
LoggingIntegration with Splunk and other platforms

Supported Platforms​

Microsoft 365 Apps (Word, Excel, PowerPoint)​

WindowsMaciOSAndroidWeb
Current Channel 2307+ · Monthly Enterprise 2309+ · Semi-Annual Enterprise 2308+16.85+2.85+16.0.18227+Not available

Outlook​

WindowsMaciOSAndroidWebNew Outlook for Windows
Current Channel 2307+ · Monthly Enterprise 2309+ · Semi-Annual Enterprise 2308+Not availableNot availableNot availableNot availableNot available

Adobe Acrobat (PDF)​

Adobe Acrobat Pro/Standard and Reader desktop apps support DKE Encryption (available from June 2023).

WindowsMaciOSAndroidWeb
23.003.20201.1ec762423.003.20201.1ec7624Not availableNot availableNot available

DKE Limitations​

Warning

Services that you cannot use with DKE encrypted content:

  • Office Web Apps including co-authoring functionality
  • Mail flow rules including anti-malware and spam
  • Microsoft Delve
  • eDiscovery
  • Content search and indexing
  • Copilot
Note

Copilot Specific Limitation: DKE encrypted data isn't accessible at rest to Microsoft 365 services including Copilot. While using your DKE encrypted data in Office, the data still isn't accessible to Copilot.

Licensing​

DuoKey DKE is an enhancement built on top of Microsoft Purview Information Protection.

DuoKey DKE Licensing​

Prices are calculated per Seat (User of Double Key Encryption identified by the EntraID/UPN) and are communicated upon request.

PackageDescription
Basic Bundle (5 Seats)Monthly subscription, includes 5 users and 1 IMGU Service, 36+ months minimum
License Package (5 Seats)Monthly subscription, package of 5 users, 1-year minimum
License Package (50 Seats)Monthly subscription, package of 50 users, 1-year minimum
Additional Guest Users (3)Package of 3 Additional Independent Microsoft Guest Users
Additional Guest Users (10)Package of 10 Additional Independent Microsoft Guest Users
Additional MPC PartitionFor DKE Segregation, 1-year minimum
Setup FeeInitial Setup Fee, one-off

Microsoft Information Protection Licenses​

Microsoft License
Office 365 E3 + Microsoft 365 E5/A5/F5/G5 Information Protection and Governance + EMS E3
Microsoft 365 E5/A5/F5/G5 Compliance + Microsoft 365 F5 Security & Compliance
Microsoft 365 E5/A5/F5/G5 Information Protection and Governance
Office 365 E5 + EMS E3
Microsoft 365 E5/A5/G5

Service Architecture & Hosting​

DuoKey MPC​

Operated from Switzerland, DuoKey DKE is globally accessible 24/7 as a cloud-based service.

LocationEndpoint
Switzerlandch01-api.duokey.cloud, ch02-api.duokey.cloud
Germanyde01-api.duokey.cloud, ch01-api.duokey.cloud
United Statesus01-api.duokey.cloud, us02-api.duokey.cloud
Singaporesg01-api.duokey.cloud, ch01-api.duokey.cloud

DuoKey DKE Hosting​

DuoKey DKE (Cockpit and DKE Service) is deployed in Google Cloud, not in Azure. Its high availability architecture allows for instant deployment within minutes, with on-premise options available upon request.

Add a New Azure Domain Name​

Warning

After adding the Azure Domain Name, you must redeploy the app for the changes to take effect—otherwise, they won't be applied. This process only takes a few seconds.

1

Navigate to Apps

Go to Apps → "App name"

2

Disable App

Click Actions → Disable

3

Enable / Deploy

Click Actions → Enable / Deploy

DKE Web Service Authentication Explained​

Authentication Flow

1
User RequestUser sends request to encrypt or decrypt the Document (CEK)
2
JWT TokenRequest includes a JWT serving as a digital ID
3
Identity ProviderMicrosoft Entra ID validates the user's identity
4
ConsentDKE Web Service needs permission from customer tenant

Enterprise Application API Permissions​

Claim ValuePermission
emailView users' email address
profileView users' basic profile
User.ReadSign in and read user profile

Cloud Exit​

You can perform a Cloud Exit using a DKE re-labeling script. This allows either replacing the current document label with a new one or removing it entirely.

Additional Resources​