Integration
Azure Blob Storage document management backend
Azure Blob Storage can serve as the DocumentMS storage backend, so document bytes are written to a container in your own Azure subscription. That puts customer-managed keys, immutable blob policies, lifecycle rules and Azure Monitor diagnostics in your hands rather than ours.
What this connection does
DocumentMS writes document bytes to a container in your own Azure Blob Storage account, selected at runtime. The application remains a managed service; the documents sit in your subscription, in your region.
This puts customer-managed keys, immutable blob policies, lifecycle management and Azure Monitor diagnostics in your hands rather than ours — which for organisations with sovereignty obligations is the difference between accepting a commitment and verifying one.
What you need on your side
- An Azure subscription and a storage account in the region you require
- A container for DocumentMS, and either a scoped SAS token or a service principal with access to it
- A decision on encryption: Microsoft-managed keys, or customer-managed keys in Azure Key Vault
- Enterprise tier, where customer-provided storage backends are available
Setting it up
Step 1: Create the container
Create a dedicated container in your storage account with the region and redundancy you need.
Step 2: Grant scoped access
Issue a SAS token or service principal limited to that container, not the whole storage account.
Step 3: Connect
Enter the account, container and credentials in DocumentMS; they are stored encrypted.
Step 4: Verify
Upload a test document and confirm the blob appears with the expected encryption and access tier.
Limits worth knowing before you rely on it
- Only document bytes move to your container. Metadata, search indexing and audit records remain platform-held — check this against your residency requirement rather than assuming
- Immutable blob policies can block deletion at the end of a retention period; align the policy with your retention schedule or disposal will fail silently
- Archive access tiers introduce a rehydration delay measured in hours; a lifecycle rule that archives active documents will make them appear unavailable
Zuletzt geprüft: 2026-09-01