Azure Database for PostgreSQL Flexible Server supports cross-tenant customer-managed keys (CMK)
Azure Database for PostgreSQL · General availability · Shipped
Description
Azure Database for PostgreSQL Flexible Server now supports cross-tenant customer-managed keys (CMK). You can encrypt your data using keys stored in an Azure Key Vault or Azure Managed HSM that resides in a different Microsoft Entra tenant than your PostgreSQL server. This update is ideal for SaaS providers and ISVs that need to keep database operations and key ownership in separate tenants. With cross-tenant CMK, you can keep full control of your encryption keys while applications and databases run in a service provider's tenant. This separation helps you meet security and compliance requirements by keeping key management independent from service operations, while allowing you to manage key rotation and revocation on your terms.[Learn more.](https://learn.microsoft.com/azure/postgresql/security/security-data-encryption#cross-tenant-customer-managed-keys-cmk-preview)
Change History
-
2026-10-01
Removed from Roadmap -
2026-10-01
Roadmap Item Added
Workload: Azure Database for PostgreSQL