Configure alerts and IP allowlist for Azure CMK

To improve transparency, Adobe provides a monitoring service that checks your key vault’s access status and triggers alerts if issues occur. These alerts help you to respond quickly and avoid service disruptions. To enable this service, allowlist Adobe’s static IP address.

IMPORTANT
If you have disabled public network access or configured your Azure Key Vault to allow only selected networks, you must add Adobe’s static IP address to your allowlist. Without it, you may not be notified of access issues that could impact your Experience Platform instance.

Allowlist Adobe’s static IP in Azure Key Vault add-adobe-static-ip

To enable these alerts while maintaining your network restrictions, navigate to your Azure Key Vault > Networking settings. In the Firewalls and virtual networks tab, select Allow public access from specific virtual networks and IP addresses.

Azure Key vault Networking settings screen showing where to add Adobe's static IP address and with the Allow access from option highlighted.

Adobe’s static IP address

IMPORTANT
The Adobe-provided static IP address is: 20.88.123.53.

Next, in the Firewall section, select Add your current IP address and replace it with Adobe’s static IP address. All outbound connections are treated as Production environments, so this static IP address must be allowlisted to ensure uninterrupted access to your key vault in restricted network configurations.

NOTE
After you add or update the static IP address in your Azure Key Vault settings, allow up to 10 minutes for the change to take effect. Once the IP has been added, the CMK app accesses the key vault to verify permissions.

After allowlisting Adobe’s static IP, Experience Platform can monitor access to your key vault and trigger alerts if issues arise. These alerts provide early warnings so you can act before service is impacted. The next section details the types of alerts you may receive and how to respond.

Monitor alerts monitor-alerts

Platform alerts notify you of issues that may interrupt key access, such as Key access failure or Key disablement. These alerts help you quickly identify problems like a removed static IP or a misconfigured firewall. To restore access, review your Azure firewall settings and re-add the required IP address.

Subscribe to Adobe I/O event notifications to receive real-time alerts in your monitoring tools. For setup instructions, see Subscribe to Adobe I/O Event notifications. You can also refer to the alerts UI guide to learn how to view and manage alerts within Experience Platform.

Next steps

You’ve now configured IP allowlisting and alert monitoring for your Azure Key Vault. To complete the setup for Customer Managed Keys in Azure, follow these configuration guides.

recommendation-more-help
eba74a00-8505-4fb5-b6a4-e3b89d0e8d1c