Skip navigation

Azure Storage Account Encryption with customer-managed key

Last updated: 2022-05-03

This template deploys a Storage Account with a customer-managed key for encryption that's generated and placed inside a Key Vault.

This Azure Resource Manager template was created by a member of the community and not by Microsoft. Each Resource Manager template is licensed to you under a licence agreement by its owner, not Microsoft. Microsoft is not responsible for Resource Manager templates provided and licensed by community members and does not screen for security, compatibility, or performance. Community Resource Manager templates are not supported under any Microsoft support programme or service, and are made available AS IS without warranty of any kind.


Parameter Name Description
location The location into which the resources should be deployed.
tenantId The Tenant Id that should be used throughout the deployment.
userAssignedIdentityName The name of the existing User Assigned Identity.
userAssignedIdentityResourceGroupName The name of the resource group for the User Assigned Identity.
keyVaultName The name of the Key Vault.
keyVaultKeyName Name of the key in the Key Vault
keyExpiration Expiration time of the key
storageAccountName The name of the Storage Account

Use the template


New-AzResourceGroup -Name <resource-group-name> -Location <resource-group-location> #use this command when you need to create a new resource group for your deployment
New-AzResourceGroupDeployment -ResourceGroupName <resource-group-name> -TemplateUri
Install and configure Azure PowerShell

Command line

az group create --name <resource-group-name> --location <resource-group-location> #use this command when you need to create a new resource group for your deployment
az group deployment create --resource-group <my-resource-group> --template-uri
Install and Configure the Azure Cross-Platform Command-Line Interface