Encryption Key Binding Changed
Sent when a customer-managed encryption key is activated or deactivated for a workload tenant.
General Information
Event ID: vdc.org_v0.kmskey_v0.binding_v0
Event message details: Sent with data.binding.action set to ACTIVATED or DEACTIVATED.
Severity: High
Workloads: Control Plane
Parameters
|
Parameter Name |
Description |
Example |
|---|---|---|
|
specversion |
Event schema version. |
20250815 |
|
source |
System that sent the event. Possible values: CONTROLPLANE, M365. |
CONTROLPLANE |
|
timestamp |
Time when the event happened, in RFC3339Nano format and the UTC time zone. |
2026-08-04T09:18:42Z |
|
type |
Event ID. |
vdc.org_v0.kmskey_v0.binding_v0 |
|
actor.kind |
Actor type that triggered the event. Possible values: user, system, service_account. |
user |
|
actor.identifier |
Actor identifier. |
admin@bob.networking |
|
organizationReference.organizationId |
ID of the Veeam Data Cloud organization. |
org_12345 |
|
data.binding.action |
Whether Bring Your Own Key (BYOK) encryption was enabled or disabled for the workload tenant. Possible values: ACTIVATED, DEACTIVATED. |
ACTIVATED |
|
data.binding.initiatingWorkload |
Workload management plane that issued the activate or deactivate call. Possible values: M365. |
M365 |
|
data.binding.workloadTenantId |
Workload tenant ID the key was bound to or unbound from. |
tenant_12345 |
|
data.kmskey.keyId |
Control-plane-derived key ID. |
b3f1c2a4-0000-0000-0000-000000000000 |
|
data.kmskey.keyDisplayName |
Display name of the key. Used as the audit target, so the action reads against a human-readable name. |
Finance Org CMK Key |
|
data.kmskey.provider |
Key Management Service (KMS) provider backing the key. Possible values:AZURE_KEY_VAULT. |
AZURE_KEY_VAULT |
|
data.org.id |
ID of the Veeam Data Cloud organization. |
org_12345 |
|
data.org.name |
Name of the Veeam Data Cloud organization. |
Alice and Bob's Networking |
Event Example
|
{ |