Read KMS offerings and resources
Step 1 of 5 in Connect Azure KMS with BYOK and BYOC.
Read before you configure. The offerings call lists the KMS kinds the deployment permits for this
tenant; if AZURE_KEY_VAULT is not offered, no amount of configuration will make it work.
Each resource carries a handle, a resourceVersion used for optimistic concurrency, and a state.
Resources move from DEGRADED through CONFIGURED to DETACHED and RETIRED. A resource that
provisioning created for the tenant (for example a software keystore) shows up here too, which tells
you whether an Azure provider is additive or a replacement for existing signing material.
A platform-owned shared vault appears as an offered shared provider rather than as a tenant resource:
Next
Continue with step 2, Configure the Azure Key Vault provider.