How to create an encryption scope protected by customer-managed keys in a different tenant in azure for the single storage account with multiple customer keys

Varun R 20 Reputation points
2025-11-09T08:14:58.4466667+00:00

Hello Azure team , wanted to know how can I create multiple encryption scopes for the customer managed keys residing in a different tenant other than my storage account's tenant . I want to extend this capability to multiple customers but with a single storage account.

  • I tried https://learn.microsoft.com/en-us/azure/storage/common/customer-managed-keys-configure-cross-tenant-existing-account?tabs=azure-portal the steps in this doc and able to add one customer key URI to my storage account inside my account . But the encryption of my storage account is getting restricted to that one single customer and I can't retrieve the other blobs which uses MMK .
  • So wanted to know if I can use multiple keys for the single storage account from multiple customer keys and that will create an encryption scope for that customer key uri will be able to upload a blob using that. Is there a way possible or there is one key per one storage account possibility in azure
Azure Storage
Azure Storage

Globally unique resources that provide access to data management services and serve as the parent namespace for the services.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.