[In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys
What the source says
Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separation of duties and ownership of encryption keys, enabling their customers to retain full control over key lifecycle management while PostgreSQL runs in a service provider's tenant. With cross-tenant CMK: Your PostgreSQL data is encrypted using a key you own and manage. The database service never has access to your key material. You can rotate or revoke keys at any time without downtime. Authentication between PostgreSQL Flexible Server and the customer-owned key vault is handled using federated identity with Microsoft Entra ID access across tenants . Learn more .
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separa
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separa
Urgency: Monitor
Next action: Review affected accounts with the customer using the official announcement.
Commercial opportunities
Use the verified change to open a scoped customer conversation.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for it_manager_dsi
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separa
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separa
Urgency: Monitor
Next action: Assess technical dependencies and ownership against the official update.
Commercial opportunities
Offer a scoped technical-readiness assessment if the customer confirms impact.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for partner_channel
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separa
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separa
Urgency: Monitor
Next action: Prepare a source-backed customer conversation and confirm the affected estate.
Commercial opportunities
Qualify a partner-led assessment only after customer scope is confirmed.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Reading for sales_manager
Who is affected: The audience described by the Microsoft update is represented by: [In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separa
Why it matters: The change matters because the official source describes: [In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separa
Urgency: Monitor
Next action: Review portfolio exposure with account owners using the official source.
Commercial opportunities
Prioritize accounts that confirm affected products or workloads.
Technical actions
Assess whether the documented change intersects the customer's current stack.
Questions to ask the customer
Does this documented change affect a product or workload in scope?
Risks and objections
The official source does not establish facts beyond the quoted material.
Points to confirm
The effective date is unknown and must be confirmed before scheduling action.
Evidence and traceability
Each excerpt is linked to the primary source. Current raw version: 261.
Raw capture : 2026-08-26T14:18:57.653130+00:00 — hash 68cb1139bba1159f…
Event
[In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separation of duties and ownership of encryption keys, enabling their customers to retain full control over key lifecycle management while PostgreSQL runs in a service provider's tenant. With cross-tenant CMK: Your PostgreSQL data is encrypted using a key you own and manage. The database service never has access to your key material. You can rotate or revoke keys at any time without downtime. Authentication between PostgreSQL Flexible Server and the customer-owned key vault is handled using federated identity with Microsoft Entra ID access across tenants . Learn more .
[In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separation of duties and ownership of encryption keys, enabling their customers to retain full control over key lifecycle management while PostgreSQL runs in a service provider's tenant. With cross-tenant CMK: Your PostgreSQL data is encrypted using a key you own and manage. The database service never has access to your key material. You can rotate or revoke keys at any time without downtime. Authentication between PostgreSQL Flexible Server and the customer-owned key vault is handled using federated identity with Microsoft Entra ID access across tenants . Learn more .
[In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separation of duties and ownership of encryption keys, enabling their customers to retain full control over key lifecycle management while PostgreSQL runs in a service provider's tenant. With cross-tenant CMK: Your PostgreSQL data is encrypted using a key you own and manage. The database service never has access to your key material. You can rotate or revoke keys at any time without downtime. Authentication between PostgreSQL Flexible Server and the customer-owned key vault is handled using federated identity with Microsoft Entra ID access across tenants . Learn more .
[In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separation of duties and ownership of encryption keys, enabling their customers to retain full control over key lifecycle management while PostgreSQL runs in a service provider's tenant. With cross-tenant CMK: Your PostgreSQL data is encrypted using a key you own and manage. The database service never has access to your key material. You can rotate or revoke keys at any time without downtime. Authentication between PostgreSQL Flexible Server and the customer-owned key vault is handled using federated identity with Microsoft Entra ID access across tenants . Learn more .
[In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separation of duties and ownership of encryption keys, enabling their customers to retain full control over key lifecycle management while PostgreSQL runs in a service provider's tenant. With cross-tenant CMK: Your PostgreSQL data is encrypted using a key you own and manage. The database service never has access to your key material. You can rotate or revoke keys at any time without downtime. Authentication between PostgreSQL Flexible Server and the customer-owned key vault is handled using federated identity with Microsoft Entra ID access across tenants . Learn more .
[In preview] Public Preview: Azure Database PostgreSQL - Flexible Server cross-tenant customer-managed keys Azure Database for PostgreSQL - Flexible Server now supports cross-tenant customer-managed keys (CMK), in public preview, allowing you to encrypt your data at rest using an Azure Key Vault key that resides in a separate Microsoft Entra tenant from the database service. This capability is designed for software as a service (SaaS) providers and enterprises that need to maintain strict separation of duties and ownership of encryption keys, enabling their customers to retain full control over key lifecycle management while PostgreSQL runs in a service provider's tenant. With cross-tenant CMK: Your PostgreSQL data is encrypted using a key you own and manage. The database service never has access to your key material. You can rotate or revoke keys at any time without downtime. Authentication between PostgreSQL Flexible Server and the customer-owned key vault is handled using federated identity with Microsoft Entra ID access across tenants . Learn more .