Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantHard

An organization is implementing Microsoft 365 and plans to use Microsoft Teams for collaboration. The security team requires that all data at rest within Microsoft Teams must be encrypted using customer-managed encryption keys (CMEK). Which Microsoft 365 feature is required to enable CMEK for Microsoft Teams data?

  1. AMicrosoft 365 Advanced Threat Protection (ATP)
  2. BMicrosoft Purview Compliance Manager
  3. CMicrosoft 365 Customer Key
  4. DMicrosoft 365 Multi-Geo Capabilities
Show answer & explanation

Correct answer: C. Microsoft 365 Customer Key

Microsoft 365 Customer Key allows organizations to provide their own encryption keys to encrypt data at rest within Microsoft 365 services, including Exchange Online, SharePoint Online, and OneDrive for Business. While Teams data is stored in these underlying services, Customer Key is the feature that enables the use of CMEK for that data.

Why the other options are wrong

  • A. ATP focuses on threat protection (email, links, attachments), not customer-managed encryption keys.
  • B. Compliance Manager helps manage compliance posture, but doesn't provide the encryption key management feature itself.
  • D. Multi-Geo allows data residency in specific geographical locations but doesn't enable customer-managed encryption keys.

Microsoft 365 Customer Key

A Microsoft 365 feature that allows customers to provide and manage their own encryption keys for data at rest in eligible Microsoft 365 services.

  • Enhances data privacy and control for customers.
  • Uses Azure Key Vault for key management.
  • Applies to Exchange Online, SharePoint Online, OneDrive, and Teams data (via underlying services).

Memory trick: Imagine your data as a treasure chest; Customer Key is like using your own special lock and key.

More Deploy and manage a Microsoft 365 tenant questions