An organization needs to implement Microsoft Purview Customer Key for Microsoft 365 to encrypt Copilot interaction data with organization-managed keys. What is a prerequisite for configuring Customer Key?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Microsoft 365 Customer Key requires provisioning two Azure Key Vault instances in two different Azure regions to provide geographic redundancy. Each Key Vault must have the 'Soft Delete' feature enabled (to prevent accidental key deletion) and 'Purge Protection' enabled (to prevent hard deletion of keys for a minimum retention period).
Full explanation below image
Full Explanation
B is correct because Microsoft 365 Customer Key requires provisioning two Azure Key Vault instances in two different Azure regions to provide geographic redundancy. Each Key Vault must have the 'Soft Delete' feature enabled (to prevent accidental key deletion) and 'Purge Protection' enabled (to prevent hard deletion of keys for a minimum retention period). These prerequisites ensure key availability and resilience before Customer Key can be configured for Microsoft 365 services including Copilot. A is wrong because Customer Key for Microsoft 365 requires Microsoft 365 E5 (or the Microsoft 365 E5 Compliance add-on), not E3. C is wrong because Entra ID P2 is required for features like PIM and Identity Protection, not for configuring Customer Key. D is wrong because the Azure Information Protection scanner is used for discovering and labeling on-premises files; it is not a prerequisite for Customer Key configuration.