Skip to main content

Configure Cloud Key Management (KMS) for Microsoft Active Directory

Updated today

After authentication, the Cloud Key Management configuration wizard appears.

Scheduled Backup of SaaS Apps data requires access to the data encryption key to encrypt backed-up data. This process is part of the digital envelope encryption process that Druva strictly adheres to. Druva does not store the userโ€™s data encryption key and has no access to the data.

Select one of the following options to generate the data encryption key.

  • Cloud Key Management System (KMS) (recommended) - Uses AWS KMS services to encrypt and decrypt SaaS Apps data. You cannot disable this setting once saved. For more information, see Configure Key Management. โ€‹

  • Bring Your Own Key (BYOK) - If your organizational policies require complete control over the encryption of the data backed up by Druva, Enterprise Key Management is the solution for you. For more information, see Enterprise Key Management.


๐Ÿ“NOTE: Scheduled backups and environment discovery will fail if KMS is not configured.


Did this answer your question?