Before you can configure DKE, you must have the following:
To provide high availability, we recommend using a Cryptographic Security Platform Vault behind a load balancer. For load-balanced clusters, the compliance label should specify the load balancer FQDN. Also include the FQDN in the SAN records for the Cryptographic Security Platform Vault certificate and when registering the Azure application that authenticates the service.
If you use a single Cryptographic Security Platform Vault instance, you can access it directly and use its FQDN.
The Cryptographic Security Platform Vault certificate should be issued by a public CA so all client systems running Microsoft Office applications trust it.