Skip to main content
Cloud / Azure / Products / Azure Key Vault Managed HSM - Single-Tenant HSM as a Managed Service

Azure Key Vault Managed HSM - Single-Tenant HSM as a Managed Service

Azure Key Vault Managed HSM: a fully managed, single-tenant HSM service using FIPS 140-3 Level 3 validated HSMs to safeguard cryptographic keys.

security
Pricing Model Billed per the "Managed HSM Pools" section on the Azure Key Vault pricing page
Availability A fully managed, highly available Azure service; each Managed HSM instance consists of a cluster of multiple HSM partitions
Data Sovereignty Per Microsoft, Managed HSM does not store or process customer data outside the region in which the customer deploys the HSM instance
Reliability Per Microsoft's Managed HSM Service Level Agreement; the preview capability External Key Management is not covered by the Managed HSM SLA SLA

Azure Key Vault Managed HSM is a fully managed, single-tenant HSM service for organizations where a multitenant key vault is not enough.

What is Azure Key Vault Managed HSM?

Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant, standards-compliant cloud service that enables you to safeguard cryptographic keys for your cloud applications using FIPS 140-3 Level 3 validated HSMs. It is one of several key management solutions in Azure.

Microsoft states the three defining properties plainly. Fully managed means the service handles HSM provisioning, configuration, patching, and maintenance. Highly available means each HSM cluster consists of multiple HSM partitions, and member partitions are automatically migrated to healthy nodes if hardware fails. Single-tenant means each instance is dedicated to a single customer and is cryptographically isolated by its own customer-specific security domain.

A note on terminology: Microsoft treats “Managed HSM instance” and “Managed HSM pool” as synonyms and uses “Managed HSM instance” consistently in the documentation.

Core Features

  • Centralized key management: manage critical, high-value keys in one place, with granular per-key permissions on the least privileged access principle
  • Isolated access control: a local RBAC model in which designated HSM cluster administrators retain complete control
  • Private endpoints: securely and privately connect to Managed HSM from an application running in a virtual network
  • FIPS 140-3 Level 3 validated HSMs: based on Marvell LiquidSecurity HSM adapters
  • Monitor and audit: fully integrated with Azure Monitor, with Azure Log Analytics for analytics and alerts
  • Data residency: no storage or processing of customer data outside the deployment region
  • BYOK: import HSM-protected keys from your own on-premises HSMs
  • Microsoft Signing Transparency: independently inspect and validate build artifacts through an immutable, tamper-evident ledger

Typical Use Cases

Customer-managed keys for Azure services
Generate or import keys and use them to encrypt data at rest in services such as Azure Storage and Azure SQL.

Customer Key for Microsoft 365
Microsoft names Customer Key for Microsoft 365 explicitly as a supported scenario.

Compliance-driven requirements
Regulatory requirements that call for single-tenant HSMs or FIPS 140-3 Level 3 validation.

Migrating existing Key Vault applications
Because Managed HSM uses the same API and management interfaces, applications can move from a multitenant vault without changing development and deployment patterns.

Sovereignty scenarios
Microsoft lists Managed HSM alongside confidential computing and external key management; the preview capability external key management addresses KEKs held outside Microsoft infrastructure.

Benefits

  • Single-tenant isolation through a customer-specific security domain
  • Access control that even subscription or management group administrators cannot override
  • Automatic migration of HSM partitions on hardware failure
  • Data residency within the region you choose
  • The same API as Key Vault, keeping migration effort low
  • Verifiable build artifacts through Microsoft’s Signing Transparency

Integration with innFactory

As an indirect Microsoft CSP partner, innFactory supports the design and operation of your key management: drawing the line between Key Vault Premium and Managed HSM, building the local RBAC model, safeguarding the security domain, BYOK processes, and connecting customer-managed-keys scenarios.

For regulated environments we place this within your compliance framework; the requirements for organizations bound by professional secrecy are covered in our article on section 203 of the German Criminal Code in the public cloud. Platform-side implementation is anchored in an Azure Landing Zone.

Contact us for a no-obligation consultation on HSM-backed key management on Microsoft Azure.

Typical Use Cases

Centrally managing critical, high-value keys
Customer-managed keys for Azure Storage, Azure SQL, and Customer Key for Microsoft 365
Compliance requirements for FIPS 140-3 Level 3 validated HSMs
Importing HSM-protected keys from your own on-premises HSMs (BYOK)
Sovereignty scenarios requiring strict separation of key custody and cloud operations

Technical Specifications

0th Fully managed: the service handles HSM provisioning, configuration, patching, and maintenance
1st Highly available: each HSM cluster consists of multiple HSM partitions; if hardware fails, member partitions are automatically migrated to healthy nodes
2nd Single-tenant: each Managed HSM instance is dedicated to a single customer and uses a separate customer-specific security domain
3rd FIPS 140-3 Level 3 validated HSMs using Marvell LiquidSecurity HSM adapters
4th Local RBAC access control model: designated HSM cluster administrators retain complete control that even management group, subscription, or resource group administrators cannot override
5th Private endpoints for secure connectivity from a virtual network
6th Fully integrated with Azure Monitor, with Azure Log Analytics for analytics and alerts
7th Uses the same API and management interfaces as Key Vault, making migration of existing applications straightforward
8th Integrated with Microsoft's Signing Transparency (MST) so customers can independently inspect and validate build artifacts
9th Managed HSM external key management is in preview, supports wrap and unwrap only, and is not covered by the Managed HSM SLA

Frequently Asked Questions

How does it differ from Azure Key Vault?

Azure Key Vault is multitenant; Managed HSM is single-tenant. Each Managed HSM instance is dedicated to a single customer and consists of a cluster of multiple HSM partitions with a separate customer-specific security domain that cryptographically isolates the cluster. Managed HSM uses the same API and management interfaces as Key Vault, so existing applications can be migrated easily.

Which FIPS level do the HSMs meet?

Microsoft describes Managed HSM as a standards-compliant cloud service using FIPS 140-3 Level 3 validated HSMs, based on Marvell LiquidSecurity HSM adapters. Microsoft also notes that the HSM fleet was updated to FIPS 140-3 Level 3 validated firmware for both Azure Key Vault Managed HSM and Azure Key Vault Premium.

Who controls access?

Managed HSM uses a local RBAC access control model. Designated HSM cluster administrators retain complete control over the HSMs, and even management group, subscription, or resource group administrators cannot override it. Granular per-key permissions can additionally be assigned on the least privileged access principle.

Where is data processed?

Microsoft states that Managed HSM does not store or process customer data outside the region in which the customer deploys the HSM instance.

Can I import my own keys?

Yes. Microsoft describes both generating keys and importing them using BYOK. You can generate HSM-protected keys in your own on-premises HSM and import them securely into Managed HSM.

What is external key management?

External key management addresses workloads that require key encryption keys (KEKs) to live in a hardware security module you operate outside Microsoft infrastructure. Managed HSM delegates wrap and unwrap operations to a customer-operated EKM proxy in front of your external HSM. Microsoft states explicitly that external key management is currently in preview, supports wrap and unwrap only, and is not covered by the Managed HSM SLA.

Which Azure services can Managed HSM be combined with?

Microsoft names Azure Storage, Azure SQL, Azure Information Protection, and Customer Key for Microsoft 365, among others. A more complete overview is in the Microsoft documentation on data encryption models.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Azure Key Vault Managed HSM - Single-Tenant HSM as a Managed Service?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation