Microsoft has opened public preview for external key management in Azure Managed HSM, enabling customers to store encryption keys on hardware they own and operate outside Microsoft datacenters. The feature addresses regulatory or contractual requirements that mandate cryptographic keys reside outside cloud provider environments, particularly in government, financial services, and critical infrastructure sectors with strict data sovereignty rules.
The preview extends Azure Managed HSM’s existing single-tenant, FIPS 140-3 Level 3 validated hardware security modules (HSMs) by adding an API endpoint that connects directly to customer-controlled HSMs. Cryptographic operations in Azure invoke external key material without exposing it to Microsoft infrastructure, maintaining the existing application interface while shifting the root of trust to customer-owned hardware.
Background: Azure Managed HSM is a dedicated hardware security module service that generates and stores encryption keys in single-tenant, FIPS 140-3 Level 3 validated hardware. Customers retain full control over key material, with Microsoft unable to access or recover keys without customer-provided security domains. The service is built on Marvell LiquidSecurity adapters and Intel SGX-based confidential computing technology.
How it works
External key management integrates with Azure Managed HSM through a dedicated API that forwards cryptographic requests to customer-operated HSMs. Applications continue using the Azure Key Vault API with customer-managed key envelope encryption patterns unchanged. When data access requires decryption of local data encryption keys, Managed HSM routes the request to the external HSM and returns the result, ensuring the external key never enters Microsoft infrastructure.
The connection between Azure and customer HSMs uses mutual TLS for authentication and encryption. Customers choose their HSM vendor or partner, as the external key management API follows an open specification supported by a growing ecosystem of hardware providers. Microsoft does not operate the integration proxy, leaving implementation to customers or their chosen partners.
Trade-offs and responsibilities
External key management shifts operational responsibility to customers, reflecting the trade-off between control and complexity. While customers gain physical control over the root of trust, they assume responsibility for the availability, provisioning, scaling, monitoring, and recovery of their HSMs and integration proxies. Disruptions on the customer side directly impact cryptographic operations and Azure service data accessibility, with Microsoft’s SLA applying only up to the point of calling the external HSM proxy.
The feature focuses on protecting data at rest and does not expose the full range of key operations available with native Managed HSM keys. Failures originating from customer-operated hardware appear in Managed HSM logs but remain the customer’s responsibility to diagnose and resolve.
For professionals: Organizations adopting external key management must evaluate whether the regulatory or contractual benefits outweigh the added operational overhead. The feature is not a security upgrade for most workloads, as native Managed HSM keys already meet or exceed sovereignty requirements without the complexity of customer-operated hardware. Teams should assess their HSM vendor’s integration support and Microsoft’s shared-responsibility model before enabling the preview.
Availability and next steps
The public preview is available in all Azure public regions, with access gated through Microsoft account teams. Pricing follows standard Managed HSM rates, with customers bearing the cost of their own hardware and any partner licensing. Microsoft has not announced a general availability timeline but indicated that customer feedback during the preview will shape operational guidance, vendor integrations, and future scenario priorities.
Automated pipeline · Cloud & Infrastructure
Synthesized from 1 industry feed on 9 Jul 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers Azure Managed HSM external key management.
- Checking for duplicates — New story pre_write:; No existing article covers Azure Managed HSM external key management.
- Writing the article — Draft created article_id=306 slug=azure-managed-hsm-adds-external-key-management-preview
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states 'addresses regulatory or contractual requirements that mandate cryptographic keys reside outside cloud provider environments' — the source specifies this is for 'highly regulated sectors such as government, financial services, and critical infrastructure, and in jurisdictions with strict data-sovereignty rules.' The draft phrasing is slightly broader but still traceable to the source. No material discrepancy.
- Style compliance: The draft uses 'Azure Managed HSM' consistently, but the source uses 'Azure Key Vault Managed Hardware Security Module (HSM)' and 'Managed HSM' interchangeably. The draft should clarify the full name on first use (e.g., 'Azure Key Vault Managed HSM, hereafter Managed HSM').
- No copied phrasing: The Background block closely echoes the source's phrasing: 'single-tenant, FIPS 140-3 Level 3 validated hardware' and 'Marvell LiquidSecurity adapters and Intel SGX-based confidential computing technology.' While factually correct, the structure mirrors the source. Restructure to avoid echoing the source's wording.
- Style compliance: The draft includes a 'For professionals' callout, which is appropriate for the audience. However, the phrasing 'The feature is not a security upgrade for most workloads' could be misread as a value judgment. Reframe to focus on the trade-off (e.g., 'For most workloads, the added control does not translate to a security improvement over native Managed HSM keys').
- Generating reader Q&A — Generated 5 items
- Assigning hero image — Reused library image pexels_id=4508751 q=customer-owned HSM in on-premises rack picker=Candidate 26 directly depicts a customer-owned HSM in an on-premises rack, which aligns perfectly with the article's foc
- Linking related stories — Linked 3 relations from 252 candidates
- Publishing — Published azure-managed-hsm-adds-external-key-management-preview
- Mastodon — Posted https://mstdn.social/@hostingpaper/116892708466212215




Discussion · coming soon
Be the first to join the thread when community discussion launches.