Creating a KEK with Azure Portal

To create a key within your recently created Key vault, click on the name of your Azure Key vault and follow the next steps.

tmp8rv0zjua.jpg


Key vaults home page

  1. Under the Settings menu select the Keys setting.

tmp6mju4ywj.png

Key vault menu

  1. Click on Generate/Import.

tmpkdn3mrf4.jpg

Default key vault keys setting page

  1. In the Options drop-down menu select Generate Key Encryption Key for importing HSM-protected Keys, add a name to the key and select the RSA key size. If needed, set the activation and expiration date for the key.

tmp0g8yzr0b.png

Example of create a key page

  1. After the key is created it will be display under the key vault created and being used, navigate to the following path to see the newly generated key.

tmp1iwf4w10.jpg

Generated keys

  1. The key we just created has an identifier which will be needed in the next steps. To find this Key Identifier, click on the newly created key in your Key Vault to display its properties. The Key Identifier will be needed in the steps for Generating and preparing your tenant key.

tmp2n9jauyh.jpg

Key properties