Hold your own key

HYOK uses an isolated on-premises AD RMS instance that provides the RMS templates based on the second different private key that's driven by an AIP label. This deployment model should be chosen for high security and compliance requirements.

Most of the time, this us used for data that can't be stored on a public cloud. This sensitive data needs to be stored and protected on-premises. Keep in mind that HYOK-protected data is typically between 3 to 5% of an organization's protected data. The following diagram shows the deployment model:

Hold your own key model

The following limitations/benefits are available by design:

Get Mastering Identity and Access Management with Microsoft Azure - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.