Policy: Azure > AI Foundry > Account > Encryption at Rest
Define the Encryption at Rest settings required for Azure > AI Foundry > Account.
Encryption at Rest refers specifically to the encryption of data when written to the underlying Cognitive Services storage. This control determines whether the account is encrypted at rest with a Microsoft managed key (the Azure default) or a customer managed key sourced from Azure Key Vault.
The Encryption at Rest control compares the encryption settings against this policy and the Customer Managed Key sub-policy, raises an alarm on mismatch, and takes the defined enforcement action.
Targets
This policy targets the following resource types:
Related Policies
Controls
Setting this policy configures this control:
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/resourceEncryptionAtRest
- tmod:@turbot/azure-aifoundry#/policy/types/accountEncryptionAtRest
- turbot graphql policy-type --id "tmod:@turbot/azure-aifoundry#/policy/types/accountEncryptionAtRest"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-aifoundry#/policy/types/accountEncryptionAtRest"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI