Key Management Definitions
Key Management Definitions
Understand DKE terminology and concepts for Microsoft 365
Tenant
A tenant is the top-level container for managing cryptographic keys. It typically represents an entire organization rather than an individual. Each key, vault, and application in DuoKey belongs to exactly one tenant. Tenants are completely isolated from each other.
Keys, vaults, and applications cannot be moved between tenants. Multiple tenants are possible if you're certain that objects won't need to be shared or moved across them.
Organization Unit
An Organization Unit in DuoKey corresponds to a business unit or department within a tenant. It represents a subdivision of an organization and is not tied to any specific user. Each vault belongs to one organization unit. Like tenants, organizations are isolated from each other.
Unlike tenants, vaults and applications can be reassigned between different organization units. Therefore, you can create multiple organizations within a tenant more flexibly.
Users
Users are identified by their email addresses. A single user can belong to one or more organization units within a tenant.
For example, an employee may belong to:
- A production organization unit
- A testing organization unit
- A personal development account
Depending on the user's role and assigned permissions, they can:
- Manage users and vaults
- Create keys
- Modify key properties
- Review activity logs
Users cannot perform cryptographic operations themselves—only registered applications can execute those operations.
Roles
DuoKey comes with a set of predefined roles per tenant, which can be customized independently to suit organizational needs:
| Role | Description |
|---|---|
| DKE-Services | Used by the DKE Web Service (e.g., Microsoft 365 Office Applications) to perform cryptographic operations. Limited to operational use and cannot perform administrative tasks. |
| DuoKey – Host | Reserved for DuoKey personnel responsible for tenant-level administration and support. |
| DuoKey – Tenant Admin | Customer administrator with administrative rights within the tenant. Can access DuoKey DKE Cockpit, create DKE Keys and Web Services, and manage users and groups. |
| DuoKey – Auditor | A read-only role with access to view keys, services, and audit/activity logs. Ideal for compliance or monitoring purposes. |
Keys
A Key is stored within a DuoKey MPC Partition (Vault) and represents either a symmetric key or an asymmetric key pair. For asymmetric keys, both the private and public components are stored together in a single Key object.
Each Key belongs to exactly one Vault. Access to a Key is governed by the permissions assigned to the Vault it resides in. Users and applications that have access to the Vault can view and operate on its Keys.
Users or applications not assigned to the Vault cannot see or interact with its Keys. For more details, see the Authorization section.
Key States
The key states conform to NIST SP800-57 - Recommendation for Key Management - Chapter 7 Key States and Transitions
| State | Description |
|---|---|
| PreActive | Key is generated on the HSM but is not yet active. If an Activation time constraint is given, the key will automatically become Active when that time is reached. |
| Active | The key can be used for cryptographic operations and is the default state. |
| Deactivated | Key cannot be used for new encrypt operations but still needed to decrypt (e.g. old encrypted files) |
| Compromised | Key known or suspected to be compromised. This key should never be used again. |
Keys that are in Deactivated or Compromised state cannot be re-activated!
Reference: NIST SP 800-57 Part 1 Rev 5 - Chapter 7 Key States and Transitions
Vaults
A Vault is a logical container for grouping related Keys. All Keys in a Vault inherit the same Access Policies and Approval Policies, which are defined at the Vault level.
Multi-User Access
Multiple users and applications can be granted access
Security Boundary
Vaults serve as the security boundary for key access
Default Setup
At least one dedicated vault per Tenant
If more vaults are needed, please contact your sales representative, or open a request on the DuoKey Support Portal.
Apps (DKE Web Service)
An Application refers to a non-human client—such as a service, daemon, or background process—that interacts with DuoKey. Applications (Microsoft 365 Office applications) authenticate to DuoKey using an API key (secret token).
Depending on assigned permissions, applications can:
- Create keys
- Modify key properties
- Perform cryptographic operations using keys
Applications cannot perform administrative tasks such as managing users or assigning access to Vaults.
An application can be assigned to one or more Vaults. Once assigned, it gains permission to operate on all Keys within those Vaults.
Conditional Access Policy (Authorization)
Conditional Access Policy enables fine-grained authorization for operations on entities such as Vaults, Keys, and Applications (Apps).
When an App interacts with a Vault or Key, the following security controls apply:
| Control | Description |
|---|---|
| Quorum Control | Allows enforcement of multi-party approvals (coming soon) |
| Role-Based Access Control (RBAC) | App permissions are defined via roles assigned to it |
| Conditional Access Policies | Fine-tuned rules that govern what the App can do |
| Status Control | Apps can be explicitly enabled or disabled |
Commonly Applied Policies
MFA Requirements
- Require MFA for administrative roles
- Enforce MFA for high-impact operations
Device Trust
- Block access from unregistered devices
- Require managed device compliance
Location Control
- Require access from trusted network locations
- Restrict or allow by geographic location
Risk-Based
- Block risky sign-in behaviors
- Detect impossible travel or anonymized IPs