How to Set Up Customer-Managed Keys for SharePoint Online and OneDrive
Question details
An organization needs to configure separate customer-managed encryption keys for partner SharePoint sites and OneDrive, including automatic labeling, decryption workflows, and controlled access.
- Product
- Microsoft SharePoint Online and OneDrive
- Device & OS
- not provided
- Scenario
- Implementing tenant-level or site-specific encryption using customer-managed keys for secure document collaboration with external partners.
- Observed behavior
- The organization requires a validated encryption architecture to apply multiple customer-managed keys to different SharePoint site collections.
Ensure you have global administrator or security administrator permissions in your Microsoft 365 tenant and an active Azure subscription with Azure Key Vault enabled.
Configure Tenant-Level Encryption with Microsoft Purview Customer Key
Use Microsoft Purview and Azure Key Vault to manage encryption keys, bearing in mind that data encryption policies are generally applied at the tenant level.
Microsoft 365 Data Encryption Policies (DEPs) are generally tenant-level. Without a multi-geo setup, you are typically limited to one policy per tenant, meaning you cannot natively assign separate encryption keys for individual SharePoint site collections natively.
Navigate to the Microsoft Purview compliance portal and configure sensitivity labels alongside auto-labeling policies for automatic data classification.
Deploy an Azure Key Vault within your Azure subscription to securely generate and store your customer-managed encryption keys.
Link Microsoft Purview Customer Key to your Azure Key Vault to apply your keys to the Microsoft 365 tenant.
Manage access to the partner sites using standard Microsoft 365 groups and SharePoint permissions, rather than relying on encryption boundaries.
Because the requirements involve complex automation and architecture, consult Microsoft Q&A or Microsoft Support for a validated design and licensing review.
Looking for a secure, lightweight alternative for document management?
Managing enterprise-level encryption in Microsoft 365 can be complex and expensive. WPS Office provides a robust, secure, and free alternative for creating, editing, and managing documents with built-in password protection and seamless compatibility with Microsoft Office formats.
- 1. Download WPS Office: Download and install the free WPS Office suite from the official website.
- 2. Open Office Files: Open your existing Microsoft Office documents directly in WPS Office without losing formatting.
- 3. Secure Your Documents: Use the 'Encrypt' feature under the 'Protect' tab to secure individual files locally with strong passwords.

Frequently Asked Questions
Can I assign a different encryption key to a specific SharePoint site?
No, under standard Microsoft 365 configurations, Data Encryption Policies (DEPs) are applied at the tenant level. You cannot assign separate customer-managed encryption keys for individual SharePoint site collections unless you utilize multi-geo capabilities.
What is Microsoft Purview Customer Key?
Microsoft Purview Customer Key allows organizations to provide and control the encryption keys used to encrypt their data at rest in Microsoft 365 services, including SharePoint Online, OneDrive, and Exchange.
Where should I store customer-managed keys for Microsoft 365?
Customer-managed keys for Microsoft 365 should be securely stored in Azure Key Vault, which integrates directly with Microsoft Purview Customer Key to handle encryption tasks.
How can I automatically classify sensitive files in OneDrive?
You can automatically classify files by configuring sensitivity labels and auto-labeling policies within the Microsoft Purview compliance portal. This ensures files are tagged and protected based on their content.




