By default, Microsoft generates and manages your tenant key for you. This is the quickest and most cost-effective way to get started with AIP with the least amount of administrative effort and would be preferable for smaller organizations.
However, you may have compliance requirements that require you to manage your own tenant key. This is known as Bring-Your-Own-Key (BYOK). You could create the key in Azure Key Vault or in an on-premise HSM (which involves a monthly cost and Azure Key Vault Premium, where you'd import it).
A tenant key can be thought of as an umbrella that can cover/contain these subkeys:
- User keys
- Computer keys
- Document encryption keys
In the next section, we will plan for WIP.