Configuring key rotation policy

Last published : Apr 17, 2026
It is recommended to rotate encryption keys at regular intervals to protect your keys. Azure Key Vault allows you to configure each key to automatically generate a new version at a specified interval. You can set up key rotation by configuring a key rotation policy, which can be defined individually for each key.
Key Vault key rotation feature requires key management permissions. You can assign the Key Vault Crypto Officer role to manage key rotation policies and perform on-demand key rotations. For the latest information about configuring the key rotation policy, refer to Key Rotation Policy.