Create Key and DKE Web Service Setup
Create Key and DKE Web Service Setup
Create DKE encryption keys and configure the web service
Login
To log in, go to DuoKey Cockpit
Login Demo
See how to log in to the DuoKey Cockpit:
Select Tenant
Click change next to Current Tenant: Not selected
Switch to Tenant
Turn on the Switch to Tenant option
Enter Tenancy Name
Enter your Tenancy Name
You can find your tenancy name in the welcome email or request it from DuoKey Support.
Create DKE Key
Access Key Creation
Navigate to the Keys tab in DuoKey Cockpit and click Create new key.
Configure Key Parameters
Enter the key configuration details:
| Field | Description | Example |
|---|---|---|
| Name | Descriptive name for your key | key_001_demo_CONFIDENTIAL-DOCUMENT |
| Description | Brief description of key purpose | Production confidential documents key |
| Vault | Select your vault instance | company_vault |
| Key Type | RSA 2048 — required by the Microsoft DKE client (RSA 4096 is not supported) | RSA 2048 |
| Key State | Active to make key immediately available | Active |
| Key Operations | Select Decrypt for decryption operations | Decrypt |
| Audit Logs | Enabled to track all key usage | Enabled |
| Enable Key | Enabled to activate the key | Enabled |
Generate the Key
Review your configuration and click Generate the Key.
The system will:
- Generate the RSA key pair in your selected vault
- Assign a unique External ID to the key
- Configure the key according to your specified parameters
- Activate the key if enabled
After key generation, the key is ready to bind to a DKE service in the next step. The DKE Access URL for Microsoft Purview labels is generated automatically when you deploy the service — see Compiling DKE Access URL below.
Key Naming Convention: Use descriptive names that indicate the key's purpose and security level:
key_confidential_financekey_topsecret_hrkey_internal_marketing
Deploy DKE Service
After creating your encryption key, you need to deploy the DKE Web Service. See the Deploy DKE Service guide for complete step-by-step instructions.
Quick Deployment Summary
Compiling DKE Access URL
After deploying the DKE Service, you need its Access URL for Microsoft Purview / MIP labels. The Access URL is the DKE service URL with a /dke/ segment and the key's identifier appended, and DuoKey Cockpit surfaces it directly on the service's details page — you don't need to build it by hand.
Fetch the DKE Access URL
- Navigate to DKE 365 → find your service → open its details
- Copy the Access URL shown there
Example DKE Access URL
https://7d8550ae-e066-4d1b-b2b8-92581e5b0aef.duokey365.com/dke/ea8afbd6-c690-4f58-8ad3-28c8bde8b261