Encryption at rest means encrypting stored data, in databases, files and backups. Anyone who gets hold of the storage without the key sees only unreadable data. Microsoft's documentation calls it "a common security requirement", and describes the threat it answers: attacks on data at rest "include attempts to obtain physical access to the hardware that stores the data and then compromise the contained data".
The standard behind it
Most systems use AES, the Advanced Encryption Standard. The AES standard itself, first published in 2001 and updated in 2023, specifies three versions: "Three members of the Rijndael family are specified in this Standard: AES-128, AES-192, and AES-256". The number is the key length in bits. Microsoft's own scheme uses "A symmetric AES-256 key" to encrypt each block of data.
What it protects against
A stolen laptop, a lost backup drive, a discarded server disk, or someone copying files directly from storage. In each case, the data is unreadable without the key.
What it doesn't
It does nothing against someone signed in with valid access. To a signed-in user, or an application acting for one, the data is decrypted automatically. That is why access controls, least privilege and audit trails matter as much.
It also stops at the edge of the system. A report exported to a spreadsheet, or a price list emailed to a colleague, is protected only by wherever it lands.
Who holds the keys
Most cloud services manage keys for you. Microsoft notes that "Most organizations can rely on platform-managed keys", while customer-managed keys give "extra control at the cost of increased management responsibility and complexity". The service still decrypts data to use it. A customer-managed key adds the power to see when the key is used, and to revoke it. Revoking it makes the data unreadable.
In a timber business
Contracts, prices, customer lists and margins are commercially sensitive. Ask each provider whether backups are encrypted too, who can use the keys, and what controls apply to exports.
Quarri's security page sets out how customer data is isolated, encrypted and audited.
Sources
- Microsoft Learn, "Azure data encryption at rest", last updated 21 July 2026: learn.microsoft.com
- NIST, FIPS 197, "Advanced Encryption Standard (AES)", published 2001, updated 9 May 2023: csrc.nist.gov
Quarri is an AI-native data platform for the timber supply chain. It connects buying, production, sales and inventory for forest management, sawmill, wood products and pulp, paper and packaging operators.