What is Managed HSM external key management?
Managed HSM external key management helps you keep your key encryption key (KEK) in a customer-owned, customer-operated HSM that runs entirely outside Microsoft infrastructure. When an Azure service needs to wrap or unwrap a data encryption key, Managed HSM delegates that operation to your external HSM through a customer-run EKM Proxy that you or your HSM vendor operate.
Microsoft explicitly labels the capability as preview and describes it as designed for organizations with strict regulatory or digital-sovereignty requirements that legally or contractually mandate physical control of key material outside Microsoft datacenters. It is, in Microsoft’s words, a last-resort, gated option rather than a general-purpose upgrade to Managed HSM keys.
Core Features
Maximum key control: The KEK never resides in or transits Microsoft infrastructure. Only your hardware performs wrap and unwrap operations.
Digital sovereignty: Because you physically control the HSM, you can disconnect it at any time to stop all cryptographic operations.
Vendor agnosticism: Microsoft publishes a standard EKM Proxy API. Any HSM vendor can implement a compliant proxy, and you can implement one yourself.
Clear responsibility boundary: Microsoft is responsible for Managed HSM up to and including the service boundary. You and your HSM vendor own everything beyond it: the proxy, the external HSM, networking, availability and support.
No Microsoft surcharge: External key management doesn’t add a per-operation fee on top of standard Managed HSM pricing. You bear the cost of your proxy infrastructure and HSM vendor licensing.
Typical Use Cases
Regulatory mandate: Supervisory or contractual requirements demand that key material stays physically outside Microsoft infrastructure.
Digital sovereignty: Organizations that need the ability to shut down cryptographic operations at any time.
Encryption at rest: Azure services that support customer-managed keys with Managed HSM encrypt data at rest with an externally held KEK.
Existing HSM estate: Continued use of existing HSM investments and vendor relationships, for example with Entrust, Eviden, Fortanix, Futurex, Securosys, Thales or Utimaco.
Benefits
- Key material stays physically in your own hardware outside Microsoft datacenters
- Ability to stop all cryptographic operations at any time
- Open, vendor-agnostic EKM Proxy API with several supporting HSM vendors
- No additional per-operation surcharge from Microsoft
- Managed HSM logs surface failures attributable to the proxy or external HSM
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you in evaluating Managed HSM external key management: assessing the regulatory necessity versus Managed HSM keys, designing the EKM Proxy and network architecture, defining an operations and availability model, and aligning with your HSM vendor.
Contact us for a no-obligation consultation on external key management and Azure key management.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
Is external key management generally available?
No. Microsoft states: 'Managed HSM external key management is in preview.' Preview features require agreeing to the supplemental terms of use, and some aspects might change before general availability.
What are the requirements to participate?
Access is gated. External key management must be enabled on your subscription by your Microsoft account team. To qualify for onboarding and use, Microsoft requires an assigned Microsoft account manager and a monetary requirement of USD 10 million or greater in overall committed Azure revenue annually.
Which operations are supported?
External key management supports wrapKey and unwrapKey only. Sign, verify, encrypt, decrypt, Secure Key Release (SKR) and confidential VM launch scenarios are out of scope.
Is there an SLA for external keys?
No. The Managed HSM SLA covers Managed HSM keys only. Availability of wrap and unwrap operations for external keys depends entirely on your proxy and HSM. Failures attributable to the proxy or external HSM don't count against the Managed HSM SLA.
Who operates and supports the EKM Proxy?
Microsoft doesn't ship, run or support the EKM Proxy or the external HSM. That responsibility belongs to you or your HSM vendor. Microsoft only publishes the EKM Proxy API against which vendors, or you, can implement a proxy.
When should external key management not be used?
If you don't have a legal or contractual requirement that mandates physical key control outside Microsoft infrastructure, Microsoft recommends using Managed HSM keys instead. External key management adds network round-trips, lowers availability and increases operational cost.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
