انتقل إلى المحتوى الرئيسي
DocumentMS

Integration

Azure Blob Storage document management backend

Azure Blob Storage can serve as the DocumentMS storage backend, so document bytes are written to a container in your own Azure subscription. That puts customer-managed keys, immutable blob policies, lifecycle rules and Azure Monitor diagnostics in your hands rather than ours.

What this connection does

DocumentMS writes document bytes to a container in your own Azure Blob Storage account, selected at runtime. The application remains a managed service; the documents sit in your subscription, in your region.

This puts customer-managed keys, immutable blob policies, lifecycle management and Azure Monitor diagnostics in your hands rather than ours — which for organisations with sovereignty obligations is the difference between accepting a commitment and verifying one.

What you need on your side

Have these ready before you start; the configuration itself takes minutes.
  • An Azure subscription and a storage account in the region you require
  • A container for DocumentMS, and either a scoped SAS token or a service principal with access to it
  • A decision on encryption: Microsoft-managed keys, or customer-managed keys in Azure Key Vault
  • Enterprise tier, where customer-provided storage backends are available

Setting it up

Test with one user and one document before rolling out. Connection events and permission changes appear in the audit trail.
  1. Step 1: Create the container

    Create a dedicated container in your storage account with the region and redundancy you need.

  2. Step 2: Grant scoped access

    Issue a SAS token or service principal limited to that container, not the whole storage account.

  3. Step 3: Connect

    Enter the account, container and credentials in DocumentMS; they are stored encrypted.

  4. Step 4: Verify

    Upload a test document and confirm the blob appears with the expected encryption and access tier.

Limits worth knowing before you rely on it

Stated up front rather than discovered later. Every integration has boundaries, and a directory that hides them just moves the discovery to a support ticket.
  • Only document bytes move to your container. Metadata, search indexing and audit records remain platform-held — check this against your residency requirement rather than assuming
  • Immutable blob policies can block deletion at the end of a retention period; align the policy with your retention schedule or disposal will fail silently
  • Archive access tiers introduce a rehydration delay measured in hours; a lifecycle rule that archives active documents will make them appear unavailable
We can set the connection up against a sandbox tenant on a demo call so you can see the behaviour rather than read about it.