DuoKey for Microsoft 365 DKE is an encryption solution designed to enhance data protection for Microsoft 365 environments. It implements Double Key Encryption (DKE), a method that uses two separate encryption keys to secure sensitive documents and data in Microsoft Office. One key is managed by Microsoft in Azure Key Vault, while the other is managed externally by the client. This approach ensures that data remains encrypted and inaccessible even if one key is compromised, maintaining data sovereignty. DuoKey for Microsoft 365 DKE utilizes secure Multi-Party Computation (MPC) to encrypt document encryption keys (DEK) with a root master key (MK), providing an additional layer of security beyond Microsoft's standard use of Hardware Security Modules (HSM). The solution integrates with Microsoft Purview to protect and control email and file sharing workflows in Microsoft 365 environments. It applies two layers of security to sensitive content in Azure cloud for Microsoft Office 365 documents and files. The MK is controlled by the customer and not accessible in clear text, ensuring cloud providers have no access to it. DuoKey for Microsoft 365 DKE replaces Microsoft's Hold Your Own Key (HYOK) by allowing customers to provide their own cryptographic keys in real time, eliminating the need for enterprise customers to operate their own Active Directory and Rights Management servers.