Skip to main content

Double Key Encryption (DKE)

Applies to:
Microsoft 365 E5Microsoft PurviewAzure RMSDuoKey MPC

Introduction & Concepts​

Modern work environments, especially those using cloud services, require advanced data protection. While standard permissions and encryption offer baseline security, Microsoft Purview Information Protection (MPIP) strengthens it by encrypting data and embedding usage rights directly with the information.

Important

For highly sensitive data, even stronger safeguards are needed—particularly protection from the cloud provider itself. This is where Double Key Encryption (DKE) comes in.

The Challenge: Protecting Sensitive Data in the Cloud​

Key Control

Cloud providers typically manage the encryption keys

Technical Access

Providers have technical ability to access encrypted data

Shared Control

Shared control poses regulatory and compliance challenges

Microsoft Purview Information Protection (MPIP)​

Before exploring DKE, it's essential to understand MPIP/Azure RMS, which DKE extends.

ComponentDescription
Microsoft Entra IDManages identities and tenant separation
Purview Information ProtectionHandles sensitivity labels and protection settings
Azure Rights Management (Azure RMS)Manages Microsoft-controlled cryptographic keys
ClientsApps (e.g., Microsoft 365) accessing protected content
DKE Web ServiceCustomer-controlled component for DKE flow

What is Double Key Encryption?​

Double Key Encryption (DKE) builds directly on top of Microsoft Purview Information Protection. It achieves maximum data confidentiality and control by introducing a second encryption key.

Two Keys

One key managed by Microsoft, second key held exclusively by you

Customer Control

Microsoft has no access to your private, second key

Data Privacy by Design

DuoKey can never access your document content

Swiss Cloud Service

HSM-protected keys with DuoKey MPC

DuoKey - DKE​

DuoKey DKE is a Swiss cloud service offering Double Key Encryption to encrypt Microsoft 365 Office documents with Hardware Security Module protected keys.

DKE Microsoft Schema

The DuoKey DKE Solution Provides​

  • The customer-controlled private key (DKE Key Management)
  • The deployment of DKE Web Service apps
  • Control of DKE service access

How Double Key Encryption Works​

How Double Key Encryption Works

Sovereign MPC-based key management for Microsoft 365

WWord
XExcel
PPowerPoint
OOutlook
AAcrobat
Sensitivity Label Applied
▼

Microsoft Purview

Azure RMS
Key 1
Microsoft-managed
Identity VerificationRights Management
+
DKE

DuoKey Sovereign KMS

MPC Vault
Key 2
Customer-controlled
Zero Trust AccessGeo-Sovereign
Key 2 secured by MPC
▼
Node A
Switzerland
Key Share A
Node B
EU Region
Key Share B
Node C
Customer DC
Key Share C

Key shares are computed together via Secure Multi-Party Computation — the full key never exists in any single location

Zero Trust Policy Check
▼
Zero Trust Access Control
User Identity
Email allowlist
Location
Country restriction
Device / IP
Network rules
IDP Groups
Azure AD / Okta
DuoKey Exclusive — no other vendor offers this
Access Granted
▼

Double Key Encrypted Document

Neither Microsoft nor DuoKey can access your data alone

Key 1+ Key 2= Decrypt

Critical Security Considerations​

Warning

DKE provides powerful control, but its security effectiveness is entirely dependent on your organization's ability to secure its components.

ConsiderationDescription
Protect Your KeyThe primary security requirement is rigorously safeguarding the customer-controlled private key
Protect IdentitiesProtecting user and administrator identities authorized to access the DKE service is critical
Identity Provider RiskUsing the same identity provider for both M365 and DKE introduces risk of single identity compromise

DKE Components​

ComponentDescription
Client FunctionalityMicrosoft 365 desktop apps on Windows (Word, Excel, PowerPoint, Outlook) and Adobe Acrobat
DKE Web ServiceWeb server component operated by DuoKey and controlled by the customer

Comparison: Standard MPIP vs. DKE​

FeatureStandard MPIPDKE (with DuoKey)
Who holds encryption key?Microsoft (cloud provider)Microsoft + Customer (DuoKey HSM)
Can Microsoft access content?Technically possible (with limitations)No access possible
Control over sensitive dataShared controlExclusive customer control
Compliance with regulationsLimited (depends on jurisdiction)Enhanced compliance

What's Next​

Vendor Documentation​

Tip

Book a 30-Minute Demo: Schedule a personalized demo to explore how DKE can benefit your organization.