Ensure Service Bus uses customer-managed keys
Service Bus namespaces should use customer-managed keys for encryption at rest.
Security Impact
Microsoft-managed keys lack fine-grained access control and rotation policies.
How to Remediate
Configure Service Bus namespace to use customer-managed keys from Azure Key Vault.
Affected Resources
Compliance Frameworks
How TigerGate Helps
TigerGate continuously monitors your Azure environment to detect and alert on this misconfiguration. Here's what our platform does for this specific check:
- Continuous Scanning
Automatically scans all Azure Service Bus resources across your Azure subscriptions every hour
- Instant Alerts
Get notified via Slack, email, or webhooks when this misconfiguration is detected
- One-Click Remediation
Fix this issue directly from the TigerGate dashboard with our guided remediation
- Compliance Evidence
Automatically collect audit evidence for SOC 2, PCI-DSS, HIPAA compliance
- Drift Detection
Get alerted if this configuration drifts back to an insecure state after remediation
Check Details
- Check ID
- azure-servicebus-1
- Service
- Azure Service Bus
- Category
- Encryption
- Severity
- MEDIUM
Automate This Check
TigerGate automatically scans your Azure environment for this and 160+ other security checks.
Start Free TrialRelated Azure Service Bus Checks
View all checksEnsure Service Bus has network access restrictions
Ensure Service Bus uses private endpoints
Ensure Service Bus has diagnostic logging enabled
Ensure Service Bus uses managed identity
Ensure Service Bus disables local authentication