Integration between BBCRM connection string rotation and clients' Azure KeyVault stores

We have recently migrated to BB hosting and are running into issues with the automatic rotation of connection strings to the read-only database every 60 days. We have implemented Azure Key Vault to make this process a bit easier, but it still requires a manual change on our side each time this happens. The rotation happens at about 2:00 or 3:00 AM and applications and integrations that are connected to the read-only DB will stop working until the password is changed in the Key Vault. If others are running into this issue, we have created an entry in the Idea Bank to have BB automatically write the new connection strings into a Key Vault. Here is the link to the idea for your review and to assist in upvoting this enhancement, Create an integration between the | Ideas for Blackbaud CRM and BBIS (aha.io).

Comments

  • David Marcucci
    David Marcucci Blackbaud Employee
    Fourth Anniversary Name Dropper Participant Facilitator 1

    Thanks @Jonathan Beyer for the idea post. I wanted to acknowledge this challenge and let you know that we're working to improve the balance of security and capabilities that offer a more streamlined way to manage activities like this.

    We're actually working with our security team right now to evaluate solutions that would enable customers to automate certain administrative tasks while still ensuring we maintain the highest degree of security. I believe this in one of those tasks, but if it isn't I'll make sure it's added to the list.

    We'll share more through our normal channels as we progress. This seems like a good spot to remind everyone about the upcoming product briefings in November!

  • Thank you @David Marcucci for the quick replying and ensuring this item is on the list. If you need testers / early adopters, please let us know and we would be happy to participate and provide feedback.

  • @Jonathan Beyer Thanks for posting this and setting up the idea. I went over there and voted for it, but wanted to mention here that this has been a big headache for us too, especially when the rotation happens over the weekend.

  • @Jonathan Beyern IMO this is the sort of thing that should be left up to the customer; if the customer wants to cycle their keys manually or automatically or not at all, it should be their choice. My 2 cents.

Categories