Skip to main content
Cloud / Azure / Products / Managed HSM External Key Management - Keys Outside Azure

Managed HSM External Key Management - Keys Outside Azure

Managed HSM external key management keeps the key encryption key in a customer-operated HSM outside Microsoft infrastructure. Currently in preview and gated.

security
Pricing Model No Microsoft per-operation surcharge; standard Managed HSM pricing plus your own proxy and HSM costs
Availability Preview in all Azure public regions at preview launch; Azure Government and Azure China are out of scope
Data Sovereignty The key encryption key remains entirely in a customer-operated HSM outside Microsoft infrastructure
Reliability No SLA covers external keys, the EKM Proxy or the external HSM SLA

What is Managed HSM external key management?

Managed HSM external key management helps you keep your key encryption key (KEK) in a customer-owned, customer-operated HSM that runs entirely outside Microsoft infrastructure. When an Azure service needs to wrap or unwrap a data encryption key, Managed HSM delegates that operation to your external HSM through a customer-run EKM Proxy that you or your HSM vendor operate.

Microsoft explicitly labels the capability as preview and describes it as designed for organizations with strict regulatory or digital-sovereignty requirements that legally or contractually mandate physical control of key material outside Microsoft datacenters. It is, in Microsoft’s words, a last-resort, gated option rather than a general-purpose upgrade to Managed HSM keys.

Core Features

Maximum key control: The KEK never resides in or transits Microsoft infrastructure. Only your hardware performs wrap and unwrap operations.

Digital sovereignty: Because you physically control the HSM, you can disconnect it at any time to stop all cryptographic operations.

Vendor agnosticism: Microsoft publishes a standard EKM Proxy API. Any HSM vendor can implement a compliant proxy, and you can implement one yourself.

Clear responsibility boundary: Microsoft is responsible for Managed HSM up to and including the service boundary. You and your HSM vendor own everything beyond it: the proxy, the external HSM, networking, availability and support.

No Microsoft surcharge: External key management doesn’t add a per-operation fee on top of standard Managed HSM pricing. You bear the cost of your proxy infrastructure and HSM vendor licensing.

Typical Use Cases

Regulatory mandate: Supervisory or contractual requirements demand that key material stays physically outside Microsoft infrastructure.

Digital sovereignty: Organizations that need the ability to shut down cryptographic operations at any time.

Encryption at rest: Azure services that support customer-managed keys with Managed HSM encrypt data at rest with an externally held KEK.

Existing HSM estate: Continued use of existing HSM investments and vendor relationships, for example with Entrust, Eviden, Fortanix, Futurex, Securosys, Thales or Utimaco.

Benefits

  • Key material stays physically in your own hardware outside Microsoft datacenters
  • Ability to stop all cryptographic operations at any time
  • Open, vendor-agnostic EKM Proxy API with several supporting HSM vendors
  • No additional per-operation surcharge from Microsoft
  • Managed HSM logs surface failures attributable to the proxy or external HSM

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports you in evaluating Managed HSM external key management: assessing the regulatory necessity versus Managed HSM keys, designing the EKM Proxy and network architecture, defining an operations and availability model, and aligning with your HSM vendor.

Contact us for a no-obligation consultation on external key management and Azure key management.

Typical Use Cases

Regulatory or contractual requirements that key material stays physically outside Microsoft infrastructure
Digital sovereignty with the ability to disconnect the HSM at any time and stop all cryptographic operations
Encryption at rest for Azure services that support customer-managed keys with Managed HSM
Continued use of existing HSM investments and vendor relationships

Technical Specifications

0th The key encryption key (KEK) stays in a customer-owned, customer-operated HSM outside Microsoft infrastructure
1st Managed HSM identifies keys with an external key identifier and forwards the operation to a customer-run EKM Proxy
2nd The EKM Proxy authenticates with the external HSM over mutual TLS (mTLS) and returns the result
3rd Supported operations: wrapKey and unwrapKey only; sign, verify, encrypt, decrypt, Secure Key Release and confidential VM launch are out of scope
4th Microsoft publishes a standard EKM Proxy API; Microsoft does not ship a proxy
5th HSM vendors supporting the API per Microsoft: Entrust, Eviden, Fortanix, Futurex, Securosys SA, Thales and Utimaco
6th Gated access: enablement by your Microsoft account team, requiring an assigned Microsoft account manager and USD 10 million or greater in overall committed Azure revenue annually
7th Networking is your responsibility: a public endpoint to the proxy, secured by mTLS
8th External key identifiers are immutable after assignment; rotate by creating new key versions
9th Backup and restore for external keys are currently not supported

Frequently Asked Questions

Is external key management generally available?

No. Microsoft states: 'Managed HSM external key management is in preview.' Preview features require agreeing to the supplemental terms of use, and some aspects might change before general availability.

What are the requirements to participate?

Access is gated. External key management must be enabled on your subscription by your Microsoft account team. To qualify for onboarding and use, Microsoft requires an assigned Microsoft account manager and a monetary requirement of USD 10 million or greater in overall committed Azure revenue annually.

Which operations are supported?

External key management supports wrapKey and unwrapKey only. Sign, verify, encrypt, decrypt, Secure Key Release (SKR) and confidential VM launch scenarios are out of scope.

Is there an SLA for external keys?

No. The Managed HSM SLA covers Managed HSM keys only. Availability of wrap and unwrap operations for external keys depends entirely on your proxy and HSM. Failures attributable to the proxy or external HSM don't count against the Managed HSM SLA.

Who operates and supports the EKM Proxy?

Microsoft doesn't ship, run or support the EKM Proxy or the external HSM. That responsibility belongs to you or your HSM vendor. Microsoft only publishes the EKM Proxy API against which vendors, or you, can implement a proxy.

When should external key management not be used?

If you don't have a legal or contractual requirement that mandates physical key control outside Microsoft infrastructure, Microsoft recommends using Managed HSM keys instead. External key management adds network round-trips, lowers availability and increases operational cost.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Managed HSM External Key Management - Keys Outside Azure?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation