OFICIAL Microsoft Azure Blog

External key management for Azure Managed HSM

What happened
Based on Microsoft Azure Blog · Jul 07, 2026

Microsoft has introduced external key management for Azure Key Vault Managed HSM in public preview, allowing organizations to store encryption keys on their own HSMs outside Azure datacenters to meet strict regulatory or sovereignty requirements.

External key management for Azure Managed HSM
Microsoft Azure Blog — Microsoft
Key points
·
Azure Key Vault Managed Hardware Security Module (HSM) provides strong sovereignty over your encryption keys.
·
Keys are generated and stored in a single-tenant, FIPS 140-3 Level 3 HSM that only you control: Microsoft has no access to your key material, and you govern who can use each key.
·
For most organizations, including those with stringent regulatory requirements, this level of control is sufficient.
Key numbers
·
Azure Key Vault Managed HSM currently stores encryption keys in dedicated, single-tenant FIPS 140-3 Level 3 HSMs within Azure datacenters, ensuring Microsoft has no access to key material.

Azure Key Vault Managed HSM currently stores encryption keys in dedicated, single-tenant FIPS 140-3 Level 3 HSMs within Azure datacenters, ensuring Microsoft has no access to key material. This setup provides strong sovereignty and control for most organizations, including those with regulatory demands. However, some entities require keys to reside physically outside Microsoft’s infrastructure due to contractual or jurisdictional obligations. The new external key management feature addresses this by enabling keys to be stored on customer-owned or third-party HSMs, either on-premises or in non-Azure environments.

External key management is designed for highly regulated sectors such as government, financial services, and critical infrastructure, where data sovereignty rules mandate that cryptographic keys must not reside within a cloud provider’s environment. The feature allows organizations to maintain the root of trust and key material on hardware they control, ensuring direct physical oversight. Microsoft emphasizes that this model should only be adopted when explicitly required, as it introduces additional operational responsibility and potential complexity compared to the standard Managed HSM approach.

The external key management capability integrates with Managed HSM through a dedicated API endpoint, enabling cryptographic operations in Azure to use keys stored on external HSMs without altering application interactions. The external key never enters or passes through Microsoft’s infrastructure; only the customer-controlled hardware processes it. Organizations can disconnect the external HSM at any time to immediately halt cryptographic operations, providing an additional layer of control and responsiveness to compliance needs.

Microsoft describes external key management as part of an ongoing effort to offer granular control over key protection, with the feature currently in public preview to gather customer feedback. The company notes that a growing ecosystem of HSM vendors is supporting integration with the external key management API, though Microsoft does not operate the integration proxy itself. Customers may use vendor-provided implementations, rely on partners, or build their own solutions, shifting operational responsibility to the customer in exchange for expanded control over the root of trust.

Original source → Deals on Clipraptor.com →