Skip to main content

Create Key and DKE Web Service Setup

Applies to:
DuoKey CockpitDKE Key CreationDKE Web Service

Login​

To log in, go to DuoKey Cockpit

Login Demo​

See how to log in to the DuoKey Cockpit:

1

Select Tenant

Click change next to Current Tenant: Not selected

2

Switch to Tenant

Turn on the Switch to Tenant option

3

Enter Tenancy Name

Enter your Tenancy Name

Note

You can find your tenancy name in the welcome email or request it from DuoKey Support.

Create DKE Key​

1

Access Key Creation

Navigate to the Keys tab in DuoKey Cockpit and click Create new key.

2

Configure Key Parameters

Enter the key configuration details:

FieldDescriptionExample
NameDescriptive name for your keykey_001_demo_CONFIDENTIAL-DOCUMENT
DescriptionBrief description of key purposeProduction confidential documents key
VaultSelect your vault instancecompany_vault
Key TypeRSA 2048 — required by the Microsoft DKE client (RSA 4096 is not supported)RSA 2048
Key StateActive to make key immediately availableActive
Key OperationsSelect Decrypt for decryption operationsDecrypt
Audit LogsEnabled to track all key usageEnabled
Enable KeyEnabled to activate the keyEnabled
3

Generate the Key

Review your configuration and click Generate the Key.

The system will:

  • Generate the RSA key pair in your selected vault
  • Assign a unique External ID to the key
  • Configure the key according to your specified parameters
  • Activate the key if enabled
Important

After key generation, the key is ready to bind to a DKE service in the next step. The DKE Access URL for Microsoft Purview labels is generated automatically when you deploy the service — see Compiling DKE Access URL below.

Tip

Key Naming Convention: Use descriptive names that indicate the key's purpose and security level:

  • key_confidential_finance
  • key_topsecret_hr
  • key_internal_marketing

Deploy DKE Service​

After creating your encryption key, you need to deploy the DKE Web Service. See the Deploy DKE Service guide for complete step-by-step instructions.

Quick Deployment Summary

1
Create New AppIn Apps tab, select DuoKey for Office 365
2
Configure DomainsEnter your Azure tenant domains
3
Select VaultChoose vault and security policies
4
Deploy ServiceTakes ~5-10 minutes
5
Verify OnlineConfirm service is accessible

Compiling DKE Access URL​

After deploying the DKE Service, you need its Access URL for Microsoft Purview / MIP labels. The Access URL is the DKE service URL with a /dke/ segment and the key's identifier appended, and DuoKey Cockpit surfaces it directly on the service's details page — you don't need to build it by hand.

Fetch the DKE Access URL​

  1. Navigate to DKE 365 → find your service → open its details
  2. Copy the Access URL shown there

Example DKE Access URL​

https://7d8550ae-e066-4d1b-b2b8-92581e5b0aef.duokey365.com/dke/ea8afbd6-c690-4f58-8ad3-28c8bde8b261

What's Next​