Generating a new tenant secret and archiving the old one is called key rotation, because your new tenant secret generates new encryption keys.

Your organization’s regulatory bodies and security policies often recommend that you rotate your tenant secrets (and keys) at specific intervals.

As we learned in the last unit, tenant secrets are used to derive your encryption keys.

You can update your tenant secret in just a few steps.

Archived tenant secrets can’t encrypt new data, but the app uses these archived keys to decrypt the data that was previously encrypted with it.

