Skip to main content

Azure Storage Encryption Scope

An Azure Storage Encryption Scope enables you to manage encryption at the container or blob level with customer-managed or Microsoft-managed keys, providing granular control over data encryption. For full details see the Encryption Scopes documentation.

Supported Methods​

  • GET: Get a specific Storage Encryption Scope by identifier
  • SEARCH: Search for Storage Encryption Scope resources by parent resource

IAM Permissions​

  • Microsoft.Storage/storageAccounts/encryptionScopes/read

azure-storage-account​

Links to the parent storage account.

azure-keyvault-vault​

Links to Azure Key Vault instances used for encryption or secret management.

azure-keyvault-key​

Links to Key Vault keys used for cryptographic operations.

dns​

Links to DNS names that resolve to this resource.