Request Demo

Microsoft Double Key Encryption (DKE) was developed for highly sensitive data. DKE uses two keys: one key controlled by the organization and a second key securely stored in Microsoft Azure. Both keys are required to access protected data.

This addresses a central question of digital sovereignty:

How can an organization prevent the cloud provider alone from accessing particularly sensitive data?

eperi sEcure also aims to give organizations greater control over their sensitive data and encryption. However, the key difference lies in the architecture and the way application functionality is handled.

DKE maximizes access control for particularly sensitive Microsoft 365 content. To achieve this, Microsoft deliberately accepts limitations on certain Microsoft 365 features. eperi sEcure, by contrast, follows a feature-preserving approach: sensitive data should be protected while retaining the functionality required for business processes.

This means two different approaches are being compared:

Microsoft DKE: Maximum control over particularly sensitive Microsoft 365 content.

eperi sEcure: Data sovereignty, protection, and preservation of functionality across cloud and SaaS applications.

DKE vs. eperi sEcure at a Glance

Criterion Microsoft DKE eperi sEcure
Two-key model Yes No, keys under the exclusive control of the customer
One key under customer control Yes Yes
Microsoft 365 native Yes No
Pre-cloud security layer No Yes
Multi-SaaS No Yes
Multi-cloud Limited/Microsoft-centric Yes
For highly sensitive data Yes Yes
Sensitivity Labels Yes In development
Platform-independent No Yes
Key management DKE-specific Yes, customer-specific


The differences are particularly relevant when it comes to preserving functionality. Microsoft documents limitations for DKE-protected content, including Copilot, eDiscovery, Content Search, indexing, Office for the Web, co-authoring, AutoSave, mobile device usage, and certain SharePoint, OneDrive, and Teams features.

How Does Microsoft DKE Work?

DKE uses two keys.

One key is controlled by the organization. The second key is located in Microsoft Azure. Both keys are required to access the protected content.

This model provides a very high degree of control over who can decrypt protected content.

At the same time, this creates an important trade-off:

If Microsoft cannot decrypt protected content, a Microsoft service cannot process that content for all functions either.

This is precisely what leads to the functional limitations of DKE.

What Is the Difference Between Microsoft Customer Key and DKE?

Customer Key and DKE should not be confused.

  • The customer controls the root keys.
  • Microsoft uses these keys within its service encryption architecture.
  • The encryption is primarily designed to protect Microsoft 365 data at rest.
  • Microsoft 365 can continue to process the data for many of its services.

DKE:

  • Two keys are required.
  • One of them is controlled by the customer.
  • The second key is located in Microsoft Azure.
  • Without both keys, the protected data cannot be accessed.
  • As a result, certain Microsoft 365 features cannot work with the protected content.

DKE therefore provides stronger separation between Microsoft and the protected content, but this comes with a deliberate loss of functionality.

How Does eperi sEcure Work?

eperi sEcure does not follow the two-key model used by DKE.

Instead, it uses a provider-independent data security layer that can protect sensitive data before it enters cloud and SaaS applications.

Depending on the use case, eperi combines encryption, tokenization, masking, and pseudonymization.

With eperi sEcure, the cloud platform also cannot access the protected data in plaintext due to the encryption. The key difference lies in preserving functionality: features that are required for working with the protected data are replicated and provided within the eperi sEcure Platform. This allows users to continue using key features of the respective cloud or SaaS application without requiring the cloud provider to access the unencrypted data.

DKE vs. Feature-Preserving Encryption

The most important difference between the two approaches becomes apparent when usability is considered alongside security.

Microsoft DKE

DKE therefore maximizes access control. However, Microsoft explicitly documents limitations for numerous features. These include Copilot, eDiscovery, Content Search, indexing, Office Web Apps, and co-authoring, among others.

eperi sEcure

eperi therefore follows a different approach:

Not only protecting data, but protecting data while preserving its business usability at the same time.

This can be particularly relevant for organizations because encryption can otherwise become an obstacle to digitalization and collaboration.

Which Features Are Restricted with Microsoft DKE?

DKE-protected data cannot be processed by all Microsoft services in the same way as regular Microsoft 365 data.

Microsoft documents limitations including:

  • Microsoft Copilot
  • eDiscovery
  • Content Search
  • Indexing
  • Office for the Web
  • Co-authoring
  • AutoSave
  • Certain SharePoint features
  • Certain OneDrive features
  • Certain Teams features
  • Certain Microsoft 365 integrations

These limitations are a direct consequence of the DKE security model.

This means:

DKE protects particularly sensitive data by heavily restricting access to that data. However, the same restriction also prevents certain features from working.

For organizations with highly sensitive data, this trade-off may be an acceptable solution. For data that needs to be regularly searched, analyzed, collaboratively edited, or processed by AI, however, it can be problematic.

Why Is Preserving Functionality So Important for Encryption?

Encryption in modern SaaS environments is not only a question of storage.

Organizations often still need to:

  • search protected data,
  • sort it,
  • analyze it,
  • collaborate on it,
  • process it automatically,
  • analyze it using AI applications,
  • use it in business processes.

If encryption prevents the application from performing these operations, a conflict arises between security and functionality.

Microsoft DKE resolves this conflict in favor of maximum access control for particularly sensitive content.

eperi sEcure, by contrast, aims to combine data sovereignty and preservation of functionality.

This can be particularly interesting for organizations that want to use cloud and AI capabilities without giving up the protection of their sensitive data.

Can Microsoft Copilot Use DKE-Protected Data?

No. Microsoft states that Copilot cannot access DKE-protected content.

This is a direct consequence of the DKE model: for Copilot to analyze content and generate responses based on it, the service would need access to the relevant data.

If access to the data is prevented by the DKE key controlled by the organization, Copilot cannot use that content.

This creates an important trade-off for organizations:

Maximum control over particularly sensitive content or maximum use of AI capabilities for that content.

eperi addresses this conflict with a different approach and positions eperi sEcure for protecting sensitive data in AI applications while preserving functionality (add-on required).

Can eperi sEcure Preserve Microsoft 365 Functionality Despite Encryption?

This is a central part of eperi's positioning.

eperi sEcure is designed to protect sensitive data without fundamentally preventing the use of the respective cloud or SaaS application.

Unlike encryption approaches where the SaaS provider can no longer process the protected content, eperi follows a feature-preserving approach.

Which specific features can actually be preserved depends on the respective application, the protection method used, and the specific use case.

For organizations, the key question is therefore not only how strongly data is encrypted, but also what employees and applications can still do with the protected data afterward.

When Does Microsoft DKE Make Sense?

Microsoft DKE is particularly relevant when:

  • Particularly sensitive documents need to be protected,
  • Maximum control over access to this data is the priority,
  • Microsoft Purview and Sensitivity Labels are being used,
  • The limitations of certain Microsoft 365 features are acceptable,
  • The protected data does not necessarily need to be processed by Copilot, Search, eDiscovery, or collaboration features.

Due to the loss of functionality, Microsoft explicitly positions DKE for particularly sensitive or business-critical data rather than as a universal encryption solution for all Microsoft 365 data.

When Is eperi sEcure Relevant?

eperi sEcure is particularly relevant when security and functionality need to be ensured simultaneously.

Typical requirements include:

  • Sensitive data should be protected without impairing important business processes,
  • Employees should be able to continue working with their familiar SaaS applications,
  • Search, sorting, or collaboration features should remain available,
  • AI applications should be used despite the protection of sensitive data,
  • Microsoft 365 is only one of several SaaS platforms,
  • Salesforce, ServiceNow, or other cloud applications should also be protected,
  • A central security policy should apply across multiple applications,
  • Data should already be protected before entering the cloud,
  • The organization does not want to tie its data security architecture to a single cloud provider.

DKE or eperi sEcure: Which Is Better for Data Sovereignty?

Both approaches can strengthen an organization's data sovereignty, but they pursue different strategies.

Microsoft DKE provides particularly strong access control within the Microsoft ecosystem. A key controlled by the organization is required to access the protected data. This prevents Microsoft from independently decrypting certain content.

eperi sEcure goes one step further toward provider-independent data security. The solution positions itself as a security layer between organizations and cloud applications.

For organizations with a Microsoft 365-only strategy that do not have a problem with feature restrictions, DKE can be an interesting option.

For organizations with a heterogeneous cloud environment or high regulatory requirements for data protection, an independent approach may offer advantages.

Why Is Provider Independence Relevant for Data Security?

When an organization manages its security entirely through the native capabilities of a SaaS provider, its data and security architecture becomes closely tied to that provider.

This can result in different security models:

This allows organizations to organize data security policies more centrally and independently of individual SaaS providers.

This is particularly relevant for multi-SaaS and multi-cloud strategies.

Conclusion

Microsoft Double Key Encryption and eperi sEcure take different approaches to increasing control over sensitive data.

DKE maximizes control over particularly sensitive Microsoft 365 content. The price is that Microsoft services can no longer access this content in some cases. As a result, certain features such as Copilot, Search, eDiscovery, Office Web Apps, or co-authoring are unavailable or restricted.

eperi sEcure takes a different approach: the solution aims to protect sensitive data while preserving the functionality required for business processes.

The key differentiation can therefore be summarized as follows:

Microsoft DKE: Maximum data control with deliberately accepted functional limitations.

eperi sEcure: Maximum data sovereignty with the goal of preserving the functionality of cloud and SaaS applications.

Another key factor is platform independence: while DKE is primarily designed for the Microsoft 365 ecosystem, eperi sEcure positions itself as a security layer across different cloud, SaaS, and custom applications.

For organizations with particularly sensitive data for which functional limitations are acceptable, DKE can be a suitable technology.

For organizations that require data sovereignty, multi-cloud security, and preservation of functionality at the same time, eperi sEcure offers a different and potentially broader approach.

FAQ

What is Microsoft Double Key Encryption?

Microsoft Double Key Encryption (DKE) is an encryption technology from Microsoft for particularly sensitive data. DKE uses two keys, one of which is controlled by the customer. Both keys are required to access protected content.

What is the difference between Microsoft DKE and eperi sEcure?

DKE is a Microsoft Purview technology for particularly sensitive Microsoft 365 content and uses a two-key model. eperi sEcure, by contrast, follows a platform-independent data-centric security approach. (LINK TO PAGE)

In addition to the architectural differences, the most important distinction lies in preserving functionality: due to its security model, DKE restricts certain Microsoft 365 features, while eperi sEcure is designed to combine protection with application functionality.

Which features do not work with Microsoft DKE?

Microsoft documents limitations including Copilot, eDiscovery, Content Search, indexing, Office for the Web, co-authoring, AutoSave, and certain SharePoint, OneDrive, and Teams features.

Can Microsoft Copilot use DKE-protected data?

No. According to Microsoft, DKE-protected content cannot be used by Copilot.

Does eperi sEcure preserve the functionality of the cloud application?

eperi sEcure follows a function-preserving approach. The goal is to protect sensitive data while preserving relevant functionality of the respective cloud or SaaS application. The specific functionality that can be preserved depends on the application and the respective use case.

Is eperi sEcure an alternative to Microsoft DKE?

Yes, depending on the use case. DKE is particularly suitable for highly sensitive Microsoft 365 content when maximum access control is the priority and functional limitations are acceptable. eperi sEcure is particularly relevant when absolute data sovereignty, preservation of functionality, and platform independence are required at the same time.

What is the difference between Microsoft DKE and Customer Key?

Customer Key uses customer-controlled root keys within Microsoft's service encryption architecture. DKE, by contrast, uses two keys, both of which are required to access protected content. DKE therefore provides stronger separation from the cloud provider, but also results in greater functional limitations.

Are DKE and eperi sEcure suitable for highly sensitive data?

Yes. Microsoft explicitly positions DKE for particularly sensitive and business-critical data. However, Microsoft does not recommend DKE as a universal encryption solution for all data, but rather for data with particularly high protection requirements because important functionality is lost.

eperi sEcure is likewise suitable for highly sensitive data while aiming to preserve functionality.

Is eperi sEcure multi-cloud capable?

Yes. eperi sEcure is designed as a platform-independent security layer and can protect different cloud, SaaS, and web applications. This makes the approach particularly suitable for heterogeneous multi-SaaS and multi-cloud environments.

Why Is Provider Independence Important for Data Security?

An independent security layer can help organizations implement data security policies and protection mechanisms consistently across multiple SaaS and cloud providers. This makes the security architecture less dependent on the native capabilities of any one cloud provider.

Can eperi sEcure protect Microsoft 365?

Yes. eperi sEcure can be used for Microsoft 365 scenarios. The approach differs from DKE: eperi does not use Microsoft's specific two-key model, but instead provides an independent data security layer focused on data sovereignty and preservation of functionality.

Are Microsoft DKE and eperi sEcure direct competitors?

To some extent. Both solutions address high requirements for data protection, encryption, and control over sensitive data. However, DKE is strongly focused on Microsoft 365 and Microsoft Purview, while eperi sEcure follows a platform-independent approach.

Do you want to use the cloud without giving up control over your data?

Learn how eperi sEcure protects sensitive data in SaaS and cloud applications.

Newsletter

Sign up for our newsletter and receive regular updates on data protection topics, changes in legislation and the further development of eperi® sEcure.