Microsoft 365Dual Key Encryption (DKE)

Protect your sensitive data with customer-controlled encryption keys.

IPS delivers fully managed Microsoft 365 Dual Key Encryption, giving your organization full control over encryption keys while securing data stored and shared in Microsoft 365.

What we do:

  • Deploy and manage Dual Key Encryption (DKE) in Microsoft 365
  • Secure sensitive data with customer-controlled encryption keys
  • Protect documents and emails with client-side encryption
  • Monitor and control encryption activity in real time
  • Ensure compliance and secure key management

Encrypt

Cloud service providers pose a risk of rogue administrators accessing customer data or encryption keys with the intent to misuse them. With DuoKey, you retain dual control of your encryption keys, ensuring that sensitive documents stored in the cloud remain secure and protected.

Protect

Employee mistakes represent the most significant threat to exposing sensitive or confidential data, whereas risks like government eavesdropping or lawful data requests are far less impactful.

Track

Stay informed with IPS's track map, which provides real-time activity logs whenever your sensitive content is decrypted using our DKE service. If you need to block access to a specific domain or user, you can easily enforce restrictions with our conditional access control rules.

Effortless Data Protection withIPS 365 Dual Key Encryption (DKE)

Secure your data effortlessly within Microsoft Office applications using IPS 365 DKE. As encryption plays a vital role in cloud data protection, its strength depends on effective key management. IPS 365 DKE operates like a Cloud Access Security Broker (CASB), encrypting sensitive data on the client side before it reaches the cloud. This ensures robust security and compliance with two encryption keys: one controlled by you and the other stored securely in Azure.

Leveraging Microsoft’s DKE framework, IPS has enhanced it with improved functionality, robustness, and enterprise-grade reliability.

For end-users, the process is simple. By selecting a sensitivity label for documents or emails, the dual encryption system between Microsoft and IPS automatically safeguards your data, even in the event of a breach.

WHAT WE DELIVER

The Benefits & Features ofIPS’s Secure Data Management

We implement and manage enterprise-grade encryption so your sensitive data stays protected—even in cloud environments.

Dual Key Encryption (DKE) Deployment & Management

We set up and manage Microsoft 365 DKE so your organization retains full control of encryption keys while securing cloud data.

Monitoring & Access Control

We track encryption activity and help enforce access restrictions using conditional access policies and security rules.

Secure Key Management (HSM Protection)

Your encryption keys are stored and protected using Hardware Security Modules (HSMs) to ensure maximum security and compliance.

Microsoft 365 Integration & Deployment

We seamlessly integrate DKE with Microsoft Purview and Azure Information Protection for smooth deployment and operation.

Client-Side Encryption Protection

Sensitive data is encrypted before it reaches Microsoft 365, ensuring it remains protected even in the event of a cloud breach.

WHY IPS

Enterprise-GradeData Protection You Control

Cloud providers reduce control over your data—IPS restores it with customer-managed encryption.

Full Control Over Encryption Keys

You retain ownership and control of your encryption keys, reducing risk from internal or external access.

Stronger Data Protection

Sensitive data stays encrypted even in cloud environments, protecting against breaches and unauthorized access.

Compliance-Ready Security

Meet regulatory and industry requirements with enterprise-grade encryption and secure key management.

Fast, Seamless Deployment

We handle setup, configuration, and integration so your encryption system is operational quickly and efficiently.