Azure Key Vault Managed HSM is a fully managed, single-tenant HSM service for organizations where a multitenant key vault is not enough.
What is Azure Key Vault Managed HSM?
Azure Key Vault Managed HSM is a fully managed, highly available, single-tenant, standards-compliant cloud service that enables you to safeguard cryptographic keys for your cloud applications using FIPS 140-3 Level 3 validated HSMs. It is one of several key management solutions in Azure.
Microsoft states the three defining properties plainly. Fully managed means the service handles HSM provisioning, configuration, patching, and maintenance. Highly available means each HSM cluster consists of multiple HSM partitions, and member partitions are automatically migrated to healthy nodes if hardware fails. Single-tenant means each instance is dedicated to a single customer and is cryptographically isolated by its own customer-specific security domain.
A note on terminology: Microsoft treats “Managed HSM instance” and “Managed HSM pool” as synonyms and uses “Managed HSM instance” consistently in the documentation.
Core Features
- Centralized key management: manage critical, high-value keys in one place, with granular per-key permissions on the least privileged access principle
- Isolated access control: a local RBAC model in which designated HSM cluster administrators retain complete control
- Private endpoints: securely and privately connect to Managed HSM from an application running in a virtual network
- FIPS 140-3 Level 3 validated HSMs: based on Marvell LiquidSecurity HSM adapters
- Monitor and audit: fully integrated with Azure Monitor, with Azure Log Analytics for analytics and alerts
- Data residency: no storage or processing of customer data outside the deployment region
- BYOK: import HSM-protected keys from your own on-premises HSMs
- Microsoft Signing Transparency: independently inspect and validate build artifacts through an immutable, tamper-evident ledger
Typical Use Cases
Customer-managed keys for Azure services
Generate or import keys and use them to encrypt data at rest in services such as Azure Storage and Azure SQL.
Customer Key for Microsoft 365
Microsoft names Customer Key for Microsoft 365 explicitly as a supported scenario.
Compliance-driven requirements
Regulatory requirements that call for single-tenant HSMs or FIPS 140-3 Level 3 validation.
Migrating existing Key Vault applications
Because Managed HSM uses the same API and management interfaces, applications can move from a multitenant vault without changing development and deployment patterns.
Sovereignty scenarios
Microsoft lists Managed HSM alongside confidential computing and external key management; the preview capability external key management addresses KEKs held outside Microsoft infrastructure.
Benefits
- Single-tenant isolation through a customer-specific security domain
- Access control that even subscription or management group administrators cannot override
- Automatic migration of HSM partitions on hardware failure
- Data residency within the region you choose
- The same API as Key Vault, keeping migration effort low
- Verifiable build artifacts through Microsoft’s Signing Transparency
Integration with innFactory
As an indirect Microsoft CSP partner, innFactory supports the design and operation of your key management: drawing the line between Key Vault Premium and Managed HSM, building the local RBAC model, safeguarding the security domain, BYOK processes, and connecting customer-managed-keys scenarios.
For regulated environments we place this within your compliance framework; the requirements for organizations bound by professional secrecy are covered in our article on section 203 of the German Criminal Code in the public cloud. Platform-side implementation is anchored in an Azure Landing Zone.
Contact us for a no-obligation consultation on HSM-backed key management on Microsoft Azure.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
How does it differ from Azure Key Vault?
Azure Key Vault is multitenant; Managed HSM is single-tenant. Each Managed HSM instance is dedicated to a single customer and consists of a cluster of multiple HSM partitions with a separate customer-specific security domain that cryptographically isolates the cluster. Managed HSM uses the same API and management interfaces as Key Vault, so existing applications can be migrated easily.
Which FIPS level do the HSMs meet?
Microsoft describes Managed HSM as a standards-compliant cloud service using FIPS 140-3 Level 3 validated HSMs, based on Marvell LiquidSecurity HSM adapters. Microsoft also notes that the HSM fleet was updated to FIPS 140-3 Level 3 validated firmware for both Azure Key Vault Managed HSM and Azure Key Vault Premium.
Who controls access?
Managed HSM uses a local RBAC access control model. Designated HSM cluster administrators retain complete control over the HSMs, and even management group, subscription, or resource group administrators cannot override it. Granular per-key permissions can additionally be assigned on the least privileged access principle.
Where is data processed?
Microsoft states that Managed HSM does not store or process customer data outside the region in which the customer deploys the HSM instance.
Can I import my own keys?
Yes. Microsoft describes both generating keys and importing them using BYOK. You can generate HSM-protected keys in your own on-premises HSM and import them securely into Managed HSM.
What is external key management?
External key management addresses workloads that require key encryption keys (KEKs) to live in a hardware security module you operate outside Microsoft infrastructure. Managed HSM delegates wrap and unwrap operations to a customer-operated EKM proxy in front of your external HSM. Microsoft states explicitly that external key management is currently in preview, supports wrap and unwrap only, and is not covered by the Managed HSM SLA.
Which Azure services can Managed HSM be combined with?
Microsoft names Azure Storage, Azure SQL, Azure Information Protection, and Customer Key for Microsoft 365, among others. A more complete overview is in the Microsoft documentation on data encryption models.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
