Azure Key Vault Managed HSM External Key Management Enters Public Preview, Empowering Unprecedented Customer Control Over Cryptographic Keys

Microsoft has officially launched the public preview of External Key Management for Azure Key Vault Managed HSM, a significant advancement in cloud security that grants organizations the ultimate authority over their encryption keys. This new capability allows businesses, particularly those in highly regulated sectors or with stringent data sovereignty mandates, to maintain their cryptographic key material on hardware physically located outside of Microsoft’s Azure datacenters, either on-premises or with a trusted third-party provider. This move directly addresses a commitment made by Microsoft approximately a year ago, signaling a dedicated effort to provide comprehensive sovereign cloud solutions.
The introduction of External Key Management builds upon the robust sovereignty already offered by Azure Key Vault Managed HSM. The existing service provides a single-tenant, FIPS 140-3 Level 3 validated Hardware Security Module (HSM) that is dedicated to each customer. Within this secure hardware environment, encryption keys are generated and stored, remaining inaccessible to Microsoft personnel, including those with administrative or physical access to the underlying infrastructure. This is achieved through a combination of dedicated hardware partitions and confidential computing technologies, such as Intel SGX, which isolate key material and cryptographic operations within hardware enclaves. Microsoft operators have no visibility into or access to the customer’s key material, ensuring a high degree of control and security.
The existing Managed HSM service already offers a powerful suite of sovereignty features:
- Single-Tenant Architecture: Each Managed HSM instance is a dedicated cluster, ensuring no resource sharing with other customers at the hardware level.
- FIPS 140-3 Level 3 Validation: The underlying HSMs meet stringent cryptographic security standards, validated by the U.S. National Institute of Standards and Technology (NIST) and Canada’s Communications Security Establishment (CSE).
- Hardware Isolation: Keys are generated and processed exclusively within the HSM, never leaving in plaintext.
- Confidential Computing: Leverages technologies like Intel SGX to create secure enclaves, further isolating sensitive operations from the host environment.
- Customer-Controlled Access Policies: Organizations dictate precisely who can access and use each key through granular role-based access control (RBAC) policies.
For the vast majority of organizations, including those navigating complex regulatory landscapes, the existing Managed HSM offering provides sufficient assurance and control. However, a specific subset of enterprises has expressed a requirement for their cryptographic keys to reside on hardware entirely outside of a cloud provider’s physical control. This is where External Key Management for Managed HSM emerges as a pivotal solution.
The Genesis of External Key Management
The impetus behind External Key Management can be traced back to growing global concerns around data sovereignty and the increasing stringency of regulatory frameworks. Jurisdictions worldwide are implementing laws that dictate where sensitive data, including cryptographic keys, must be stored and processed. For instance, the European Union’s General Data Protection Regulation (GDPR) has broad implications for data privacy, while specific national regulations in countries like Germany or Australia may impose even stricter requirements on data localization.
Microsoft’s announcement of comprehensive sovereign solutions in June 2023, specifically highlighted in a blog post by its executive leadership, signaled a strategic response to these evolving market demands. The commitment made then has now materialized with the public preview of External Key Management, demonstrating Microsoft’s responsiveness to customer needs and its dedication to empowering organizations with greater control in cloud environments.
What External Key Management Enhances
While Managed HSM already delivers robust sovereignty through dedicated hardware and strict access controls within Azure, External Key Management introduces a singular, yet profound, capability: the option to keep key material on hardware that the customer exclusively owns and operates. This can be an on-premises data center, a colocation facility, or infrastructure managed by a trusted, independent third-party provider.
This capability is specifically designed for scenarios where regulatory mandates or contractual obligations explicitly prohibit cryptographic keys from residing within the cloud provider’s infrastructure. Such requirements are commonly encountered in:
- Government and Defense: Sectors dealing with highly sensitive national security information.
- Financial Services: Banks and other financial institutions often face strict regulations regarding data residency and the protection of financial transaction keys.
- Critical Infrastructure: Energy, utilities, and telecommunications sectors managing essential services that require the highest levels of security and compliance.
- Jurisdictions with Strict Data Sovereignty Laws: Countries that enforce stringent rules on data being kept within their national borders.
In these contexts, External Key Management ensures that the "root of trust" and the actual key material remain under the customer’s direct physical control, completely divorced from Microsoft’s cloud infrastructure.
However, Microsoft emphasizes that this model is not a universal upgrade in security. For most workloads, the native Managed HSM remains the recommended approach. This is due to its inherent advantages:
- Higher Native Availability: Managed HSM benefits from Azure’s robust global infrastructure, ensuring high availability and disaster recovery capabilities without additional customer effort.
- Reduced Operational Complexity: Managing on-premises or third-party HSMs introduces significant operational overhead, including hardware maintenance, patching, physical security, and personnel training.
- Optimized Security Posture: The integrated security and operational efficiencies of Managed HSM often exceed the baseline security requirements without introducing the complexities and potential risks associated with managing external hardware.
External Key Management is positioned as a solution for specific, stringent regulatory constraints, not as a general enhancement to baseline security. When these constraints are not in play, Managed HSM offers a more secure, reliable, and operationally efficient pathway.
Under the Hood: How External Key Management Operates
The functionality of External Key Management is facilitated through a dedicated API endpoint within Azure Key Vault Managed HSM. This endpoint establishes a secure connection directly to the customer-controlled HSM. This architectural design allows cryptographic operations initiated within Azure services to leverage external key material without requiring any modifications to how applications typically interact with Azure Key Vault.
Crucially, the external key material itself never resides within, nor does it transit through, Microsoft’s cloud infrastructure. It is exclusively managed and utilized by the customer’s own hardware. The inherent control this provides is absolute: if the customer disconnects their external HSM, all cryptographic operations that rely on those keys within Azure are immediately halted. This offers an unparalleled level of control and immediate kill-switch capability.
The operational flow can be visualized as follows:
- An Azure service requires a cryptographic operation (e.g., encrypting data, signing a transaction).
- Instead of invoking a key within Managed HSM, the request is routed via the dedicated API endpoint to the customer’s external HSM.
- The external HSM performs the cryptographic operation using the customer’s key material.
- The result of the operation (e.g., ciphertext, signature) is returned to the Azure service.
- The key material itself never leaves the customer’s controlled environment.
The Expanding HSM Ecosystem
Recognizing the critical nature of this capability, Microsoft has fostered the development of an ecosystem of Hardware Security Module (HSM) vendors. A growing number of providers are actively working to ensure their platforms are compatible with the Managed HSM External Key Management API. This collaborative approach allows customers to select HSM solutions from a range of trusted vendors that align with their specific requirements and existing infrastructure.
In a departure from some cloud provider models, Microsoft does not build or operate the integration proxy itself. Instead, it embraces an open model. This empowers customers with flexibility:
- Vendor-Provided Implementations: Utilize proxy solutions developed and maintained by HSM vendors.
- Partner Operations: Engage with third-party partners to manage and operate the integration proxy.
- Self-Built Solutions: For organizations with the necessary expertise, the option exists to build and maintain their own integration proxy.
This open approach ensures that customers are not locked into a single vendor solution and can leverage their preferred partners or in-house capabilities.
Responsibilities and Trade-offs: A New Paradigm of Control
The introduction of External Key Management deliberately shifts a portion of operational responsibility from Microsoft to the customer. This is a direct consequence of extending the trust boundary beyond the confines of Azure. The customer gains direct control over the root of trust, and with that control comes the ownership and responsibility for the systems that enforce it.
The core trade-off can be succinctly stated: more control equals more responsibility.
Key areas where customers assume new responsibilities include:
- HSM Hardware Management: Customers are responsible for the procurement, installation, configuration, and ongoing maintenance of their own HSM hardware. This includes ensuring physical security, power, cooling, and network connectivity.
- HSM Software and Firmware Updates: Keeping the HSMs running the latest, secure versions of their operating systems and firmware is a customer responsibility.
- Key Lifecycle Management: While Managed HSM provides tools for key management, the ultimate responsibility for key generation, rotation, backup, and destruction rests with the customer when keys are external.
- Integration Proxy Operations: If a vendor-provided or self-built proxy is used, the customer is responsible for its deployment, monitoring, and maintenance.
- Disaster Recovery and Business Continuity: Customers must implement their own robust disaster recovery and business continuity plans for their external HSM infrastructure.
- Security of the External Environment: The security of the physical location and network perimeter where the external HSM resides is entirely under the customer’s purview.
This shift requires a significant investment in expertise, resources, and processes. Organizations must carefully assess their capabilities and requirements before opting for this model.
Public Preview Scope and Future Development
The current public preview phase is designed to gather crucial feedback from early adopters. During this period, Microsoft is focusing on several key areas:
- Core Functionality: Ensuring the reliable operation of the External Key Management API and its integration with Azure services.
- Vendor Integrations: Collaborating with initial HSM partners to validate and refine their integration proxies.
- Operational Guidance: Developing comprehensive documentation and best practices for customers managing external HSMs.
- Scenario Prioritization: Understanding the specific use cases and regulatory drivers that are most critical for customers.
Microsoft has indicated that customer feedback received during the preview will directly influence the feature’s path to general availability. This includes prioritizing operational guidance, expanding vendor integrations, and focusing on the most impactful customer scenarios for future development.
Getting Started with External Key Management
Organizations interested in exploring External Key Management can begin by familiarizing themselves with the prerequisites and deployment steps outlined in the Azure documentation. This typically involves:
- Configuring an Azure Key Vault Managed HSM: Setting up a Managed HSM instance within Azure.
- Deploying and Configuring an External HSM: Ensuring the customer’s own HSM is operational and accessible.
- Establishing the Integration Proxy: Setting up the connection between the Azure Managed HSM and the external HSM.
- Defining Access Policies: Configuring appropriate access controls within Azure Key Vault.
The public preview offers an invaluable opportunity for organizations to test this advanced capability in a controlled environment and provide direct input to Microsoft. By participating, customers can help shape the future of cloud key management and ensure that sovereign cloud solutions meet the evolving needs of global enterprises.
External Key Management represents a significant step forward in Microsoft’s commitment to providing customers with granular control over their data and security in the cloud. It underscores a growing trend towards specialized security solutions tailored to meet the unique and often stringent requirements of regulated industries and data-conscious nations. As the technology matures and the ecosystem expands, it promises to empower a broader range of organizations to leverage the cloud while maintaining ultimate sovereignty over their most sensitive cryptographic assets.







