Azure Key Vault Managed HSM External Key Management Enters Public Preview, Empowering Unprecedented Data Sovereignty

Microsoft Azure has officially launched the public preview of External Key Management for Azure Key Vault Managed HSM, a significant advancement in cloud security that grants organizations enhanced control over their cryptographic keys. This new capability directly addresses the stringent requirements of a growing number of businesses, particularly those in highly regulated industries and jurisdictions, by allowing them to maintain their encryption key material on hardware physically located outside of Microsoft’s datacenter infrastructure. This move fulfills a commitment made by Microsoft approximately one year ago to provide more comprehensive sovereign cloud solutions, signaling a strategic push to accommodate diverse global compliance needs.
The introduction of External Key Management for Managed HSM represents a pivotal moment for organizations grappling with complex regulatory landscapes and demanding data sovereignty mandates. While Azure Key Vault Managed HSM has long offered robust security and control by generating and storing keys within dedicated, single-tenant, FIPS 140-3 Level 3 certified Hardware Security Modules (HSMs) that Microsoft itself cannot access, the new preview feature extends this control to the physical location of the key-holding hardware. This allows customers to choose to house their critical cryptographic keys on their own premises or with a trusted third-party provider, completely independent of the Azure cloud environment.
The Evolving Landscape of Cloud Security and Sovereignty
The demand for advanced data sovereignty solutions has surged in recent years, driven by a confluence of factors. Increasingly stringent data protection regulations, such as the European Union’s General Data Protection Regulation (GDPR) and similar legislation emerging globally, have placed a premium on where and how sensitive data is stored and processed. For many organizations, particularly those operating in sectors like government, finance, and critical infrastructure, the physical location of their encryption keys is not merely a technical consideration but a fundamental legal and compliance requirement.
Microsoft’s commitment to addressing these needs was articulated by key executives in June 2025, emphasizing a dedication to building comprehensive sovereign solutions tailored for specific regional and industry demands. The public preview of External Key Management for Managed HSM is a tangible realization of that strategic vision, offering a sophisticated solution that bridges the gap between the security and scalability of cloud services and the absolute control demanded by the most sensitive workloads.
How Azure Key Vault Managed HSM Delivers Sovereignty Today
Before delving into the nuances of external key management, it is crucial to understand the inherent sovereignty offered by the existing Azure Key Vault Managed HSM service. At its core, Managed HSM is a single-tenant service, meaning each customer instance is provisioned with a dedicated cluster of FIPS 140-3 Level 3 validated HSM partitions. These partitions are built upon Marvell LiquidSecurity adapters, a robust hardware foundation designed for high-security cryptographic operations.
A key tenet of Managed HSM’s security model is that encryption keys are generated internally within this hardware and crucially, never leave the HSM in plaintext. This fundamental design principle ensures that Microsoft operators, even those with administrative or physical access to the underlying infrastructure, are unable to access or view a customer’s sensitive key material.
Furthermore, Managed HSM leverages confidential computing technology, including Intel SGX, to create hardware enclaves. Within these enclaves, request handling, access control logic, and the key material itself are isolated. This isolation is maintained at the hardware level, providing an additional layer of protection that prevents any external observation or interference, including from Microsoft personnel. This sophisticated combination of single-tenancy, FIPS 140-3 Level 3 certification, and confidential computing ensures redundancy, isolation, and robust protection, offering organizations the sovereignty assurances they require without compromising on key security, operational complexity, or service availability. Control over key usage and access remains firmly in the hands of the customer.
The Added Value of External Key Management
While Managed HSM already provides a high degree of customer control and enterprise-grade security, External Key Management introduces a distinct capability: the option to situate the hardware that manages cryptographic keys entirely outside of Microsoft’s cloud infrastructure. This means organizations can opt to host their key material on HSMs they own and operate, either on-premises within their own facilities or through a trusted third-party colocation or managed service provider.
This new feature is specifically designed to cater to scenarios where regulatory mandates or contractual obligations explicitly stipulate that cryptographic keys must reside outside the cloud provider’s operational domain. Such requirements are commonly encountered in sectors with rigorous compliance frameworks, including national governments, major financial institutions, and operators of critical national infrastructure. Moreover, it addresses the needs of organizations subject to strict data sovereignty laws in various jurisdictions that may restrict the extraterritorial processing or storage of sensitive data, including the underlying keys.
External Key Management ensures that the root of trust – the foundational element of any cryptographic system – and the associated key material remain on hardware that is under the customer’s direct physical control and management, completely detached from Microsoft’s infrastructure.
Strategic Considerations and Recommended Use Cases
Microsoft emphasizes that External Key Management is a deliberate choice, intended for adoption only when specific regulatory or contractual obligations necessitate it. For the vast majority of workloads, the native Managed HSM offering remains the recommended approach. This is due to its inherent advantages, including higher native availability, significantly reduced operational complexity, and a security posture that not only meets but often exceeds typical sovereignty requirements without introducing additional risks or operational overhead.
The core message is that External Key Management is a solution for meeting specific, often stringent, regulatory constraints rather than an incremental step to enhance baseline security for all users. When these unique constraints are not present, the integrated Managed HSM service provides a more robust, reliable, and operationally efficient solution. The trade-off for enhanced physical control via external key management involves a shift in operational responsibility, which must be carefully considered.
How External Key Management Operates
The External Key Management feature extends the capabilities of Managed HSM through a dedicated API endpoint. This endpoint establishes a secure connection directly to the customer-controlled HSM. Crucially, this integration allows cryptographic operations initiated within Azure services to leverage external key material without requiring any modifications to how applications interact with the Managed HSM service.
The fundamental security principle is that the external key material itself never resides within, nor does it transit through, Microsoft’s cloud infrastructure. Only the customer’s privately owned and managed hardware directly utilizes these keys. Because the customer exercises full control over this external hardware, they possess the ability to disconnect it at any moment, thereby instantaneously halting all associated cryptographic operations within Azure. This provides an ultimate failsafe and a tangible demonstration of direct physical control.
The Growing HSM Ecosystem for External Key Management
Microsoft has fostered an open ecosystem for External Key Management, recognizing that a diverse range of hardware security module vendors will play a crucial role in its adoption. A growing number of HSM providers are actively working to ensure their platforms are compatible with the Managed HSM External Key Management API. This collaborative approach allows organizations to select hardware solutions that best fit their existing infrastructure, security policies, and operational preferences.
It is important to note that Microsoft does not develop or operate the connecting integration proxy itself. Instead, customers benefit from a flexible, open model. They can opt to utilize a vendor-provided implementation of the integration proxy, engage a partner to manage its operation, or even develop their own solution if they possess the requisite in-house expertise. This distributed responsibility model underscores Microsoft’s commitment to empowering customer choice and control.
Responsibilities and Trade-offs in External Key Management
The introduction of External Key Management deliberately shifts a portion of operational responsibility to the customer. This is a direct consequence of extending the trust boundary beyond the confines of Azure. By gaining ultimate control over the root of trust, customers also assume ownership and accountability for the systems and processes that enforce that trust.
This represents the fundamental trade-off: increased control inherently comes with increased responsibility. Customers are now responsible for:
- Procurement and Deployment: Selecting, acquiring, and physically deploying their own HSM hardware.
- Physical Security: Ensuring the physical security of the HSMs and the environment in which they are housed.
- Operational Management: Managing the lifecycle of the HSMs, including patching, firmware updates, and regular maintenance.
- High Availability and Disaster Recovery: Implementing robust high availability and disaster recovery strategies for their external HSM infrastructure to ensure uninterrupted cryptographic services.
- Monitoring and Auditing: Establishing comprehensive monitoring and auditing mechanisms for their external HSMs.
- Integration Proxy Management: Ensuring the secure and reliable operation of the integration proxy that connects their HSMs to Azure.
These responsibilities necessitate dedicated resources, specialized expertise, and a commitment to maintaining the highest standards of operational rigor. While Managed HSM abstracts away much of this complexity, External Key Management places it directly in the hands of the customer, offering unparalleled control at the cost of increased operational overhead.
Public Preview Scope and Future Development
The current public preview phase of External Key Management for Azure Key Vault Managed HSM is designed to gather critical feedback from early adopters. During this period, Microsoft is actively soliciting input from customers to help shape the feature’s trajectory towards general availability. This feedback will directly influence the development of operational guidance, the expansion of vendor integrations, and the prioritization of specific use cases and scenarios.
Microsoft’s approach to cloud security has always been iterative and customer-centric, and this initiative is no exception. The insights gained during the public preview will be instrumental in ensuring that External Key Management is a robust, secure, and user-friendly solution that meets the diverse and evolving needs of global organizations.
Getting Started with External Key Management
Organizations interested in exploring the capabilities of External Key Management for Azure Key Vault Managed HSM are encouraged to engage with the public preview. Detailed documentation and guidance are available through Microsoft’s Azure documentation portal. This typically involves:
- Consulting Prerequisites: Reviewing the technical prerequisites and compatibility requirements for both Azure Key Vault Managed HSM and the chosen external HSM hardware.
- Setting up the Integration: Following the provided instructions to configure the secure connection between the customer-controlled HSM and the Azure API endpoint.
- Testing and Validation: Conducting thorough testing of cryptographic operations to ensure seamless integration and verify that all security and compliance objectives are met.
- Providing Feedback: Actively participating in feedback mechanisms to help Microsoft refine the service.
External Key Management represents the latest stride in Microsoft’s ongoing commitment to providing customers with granular control over how and where their sensitive data and cryptographic keys are protected. As the feature progresses from public preview to general availability, it is poised to become an indispensable tool for organizations navigating the complex intersection of cloud adoption and stringent data sovereignty requirements, reinforcing Azure’s position as a leading platform for secure and compliant cloud computing.







