Azure

Azure Managed HSM External Key Management Preview

3 min read

Summary

Microsoft has launched external key management for Azure Key Vault Managed HSM in public preview, letting organizations keep encryption keys on HSMs they own outside Azure. The feature is aimed at regulated environments that require physical control of key hardware, but it also shifts availability and operational responsibility to the customer or partner.

Need help with Azure?Talk to an Expert

Introduction

Microsoft has announced public preview support for external key management in Azure Key Vault Managed HSM. This gives organizations a new option to keep key material on HSM hardware they own and operate outside Microsoft datacenters, while still using Azure services that rely on customer-managed keys.

For most customers, standard Managed HSM remains the recommended model. But for government, financial services, and other regulated sectors, this preview addresses requirements for physical key custody outside the cloud provider environment.

What’s new

External key management for Managed HSM

Azure Managed HSM now supports a dedicated API endpoint that can connect to an external HSM under customer control. This means:

  • Key material can remain on customer-owned or partner-operated hardware
  • The external key does not reside in Microsoft infrastructure
  • Applications continue using Managed HSM and Azure Key Vault APIs without major changes
  • Azure forwards supported cryptographic requests to the external HSM when needed

Open integration model

Microsoft is using an open specification for the external key management API. Customers can:

  • Use a vendor-provided integration
  • Work with a trusted partner
  • Build their own implementation

Connections between Azure and the external HSM are secured with mutual TLS.

Preview scope

At launch, the preview includes:

  • Availability in all Azure public regions
  • Support for data-at-rest protection scenarios tied to customer-managed keys
  • Gated access, enabled through your Microsoft account team
  • No added Microsoft surcharge beyond standard Managed HSM pricing

Why it matters for IT admins

This preview is important for organizations with strict sovereignty, regulatory, or contractual obligations that require encryption keys to stay outside Azure datacenters.

However, Microsoft is clear about the tradeoff: more control means more responsibility. With external key management, customers are responsible for:

  • External HSM and proxy availability
  • Provisioning, scaling, and recovery
  • Monitoring and troubleshooting failures on their side
  • Any partner licensing or hardware costs

If the external HSM or proxy is unavailable, cryptographic operations can fail and impact access to protected Azure data.

  • Confirm whether your compliance requirements truly require keys outside Azure
  • Review the Managed HSM shared responsibility model and SLA boundaries
  • Evaluate HSM vendor or partner support for the external key management API
  • Contact your Microsoft account team to request preview access
  • Test availability, failover, and operational runbooks before production use

For most deployments, native Managed HSM keys will still offer the best balance of security, resilience, and operational simplicity. External key management is best reserved for scenarios where physical key residency outside Azure is mandatory.

Need help with Azure?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Azure Managed HSMAzure Key Vaultencryption keysHSMcustomer-managed keys

Related Posts

Azure

SQL Server on Azure Local GA for Edge and Sovereign

Microsoft has announced general availability of SQL Server on Azure Local for both connected and disconnected environments. The release gives organizations a consistent way to run mission-critical SQL Server workloads close to their data, while supporting Azure Arc management, existing licensing benefits, and local AI scenarios with Foundry Local in preview.

Azure

Microsoft Fabric 2026: Copilot and Power BI Updates

At FabCon and SQLCon 2026, Microsoft announced new Microsoft Fabric and SQL innovations focused on grounding Copilot and agents in trusted enterprise data. Highlights include Fabric IQ integration with Microsoft Copilot, agentic app creation in Power BI Desktop, Fabric Apps enhancements, and new observability and database management capabilities.

Azure

Azure VM Lifecycle Policy: New Stages for Modernization

Microsoft has introduced a clearer Azure Virtual Machine lifecycle policy to help customers plan infrastructure transitions with more transparency and predictability. The new framework defines Current, Extended, End of Life, and Retired stages for key VM families, along with guidance, availability expectations, and modernization tools for affected workloads.

Azure

Microsoft Foundry Adds Voice Agents and GPT-6

Microsoft Foundry has expanded its AI agent platform with broader model choice, native voice agents, and tools for continuous optimization. The update gives Azure teams more flexibility to evaluate frontier models like GPT-6 and Claude Opus 5.5, build multilingual voice experiences, and improve agent quality, latency, and cost over time.

Azure

Claude Opus 5.5 in Microsoft Foundry for AI Agents

Microsoft Foundry now offers Claude Opus 5.5, Anthropic’s latest model aimed at long-running coding, knowledge work, and agent-based workflows. The update matters to Azure teams because it adds adaptive reasoning, clearer agent communication, and new capabilities for managing long-context tasks in production.

Azure

Azure Resilience Drift: Why Diagrams Are Not Enough

Microsoft is urging organizations to treat resilience as a continuously validated operational capability, not a one-time architecture exercise. The article highlights how configuration drift, AI dependencies, and untested failover paths can undermine resilient designs even when architecture diagrams still look correct.