Encryption Key Binding Changed

Sent when a customer-managed encryption key is activated or deactivated for a workload tenant.

General Information

Event ID: vdc.org_v0.kmskey_v0.binding_v0

Event message details: Sent with data.binding.action set to ACTIVATED or DEACTIVATED.

Severity: High

Workloads: Control Plane

Parameters

Parameters

Parameter Name

Description

Example

specversion

Event schema version.

20250815

source

System that sent the event. Possible values: CONTROLPLANE, M365.

CONTROLPLANE

timestamp

Time when the event happened, in RFC3339Nano format and the UTC time zone.

2026-08-04T09:18:42Z

type

Event ID.

vdc.org_v0.kmskey_v0.binding_v0

actor.kind

Actor type that triggered the event. Possible values: user, system, service_account.

user

actor.identifier

Actor identifier.

admin@bob.networking

organizationReference.organizationId

ID of the Veeam Data Cloud organization.

org_12345

data.binding.action

Whether Bring Your Own Key (BYOK) encryption was enabled or disabled for the workload tenant. Possible values: ACTIVATED, DEACTIVATED.

ACTIVATED

data.binding.initiatingWorkload

Workload management plane that issued the activate or deactivate call. Possible values: M365.

M365

data.binding.workloadTenantId

Workload tenant ID the key was bound to or unbound from.

tenant_12345

data.kmskey.keyId

Control-plane-derived key ID.

b3f1c2a4-0000-0000-0000-000000000000

data.kmskey.keyDisplayName

Display name of the key. Used as the audit target, so the action reads against a human-readable name.

Finance Org CMK Key

data.kmskey.provider

Key Management Service (KMS) provider backing the key. Possible values:AZURE_KEY_VAULT.

AZURE_KEY_VAULT

data.org.id

ID of the Veeam Data Cloud organization.

org_12345

data.org.name

Name of the Veeam Data Cloud organization.

Alice and Bob's Networking

Event Example

{
  "specversion": "20250815",
  "source": "CONTROLPLANE",
  "timestamp": "2026-08-04T09:18:42Z",
  "type": "vdc.org_v0.kmskey_v0.binding_v0",
  "actor": {
    "identifier": "admin@bob.networking",
    "kind": "user"
  },
  "organizationReference": {
    "organizationId": "org_12345"
  },
  "data": {
    "binding": {
      "action": "ACTIVATED",
      "initiatingWorkload": "M365",
      "workloadTenantId": "tenant_12345"
    },
    "kmskey": {
      "keyId": "b3f1c2a4-0000-0000-0000-000000000000",
      "keyDisplayName": "Finance Org CMK Key",
      "provider": "AZURE_KEY_VAULT"
    },
    "org": {
      "id": "org_12345",
      "name": "Alice and Bob's Networking"
    }
  }
}