OpsCanary
azureidentityPractitioner

Unlocking Control: External Key Management for Azure Managed HSM

5 min read Azure BlogJul 7, 2026Reviewed for accuracy
Share
PractitionerHands-on experience recommended

Azure's External Key Management for Managed HSM exists to provide organizations with stringent regulatory requirements a way to maintain sovereignty over their encryption keys. By allowing you to keep your key material on an HSM that you own, either on-premises or with a trusted third party, it addresses the need for enhanced control while still leveraging Azure's capabilities.

This feature extends Managed HSM through a dedicated API endpoint that connects directly to your controlled HSM. When applications perform cryptographic operations, they can invoke external key material seamlessly, without altering how they interact with Azure services. Importantly, the external key never resides in or traverses Microsoft infrastructure; it is solely utilized by your hardware. This setup ensures that your security domain remains cryptographically isolated, governed by multiperson control through RSA key pairs that you manage offline.

In production, consider that while this model offers greater control, it also brings added responsibility. For most workloads, sticking with Managed HSM keys is recommended due to their higher availability and reduced operational complexity. Remember, external key management is tailored for specific regulatory constraints rather than enhancing baseline security. Access to this feature is gated; you need to contact your Microsoft account team to enable it on your Managed HSM.

Key takeaways

  • Understand that External Key Management allows you to keep key material on an HSM you control.
  • Utilize a dedicated API endpoint to connect directly to your controlled HSM for cryptographic operations.
  • Recognize that external keys never pass through Microsoft infrastructure, enhancing your sovereignty.
  • Acknowledge that adopting this model increases your responsibility for key management.
  • Contact your Microsoft account team to enable external key management on your Managed HSM.

Why it matters

This feature is crucial for organizations facing strict regulatory requirements, enabling them to maintain control over encryption keys while leveraging Azure's cloud capabilities.

When NOT to use this

External key management is about meeting specific regulatory constraints, not increasing baseline security. If your workloads don't have stringent compliance needs, consider sticking with Managed HSM keys for better availability and simplicity.

Want the complete reference?

Read official docs

Test what you just learned

Quiz questions written from this article

Take the quiz →
DigitalOceanSponsor

Simple, affordable cloud — VMs, Kubernetes, and managed databases in minutes. Trusted by 600,000+ developers. Spin up a Droplet in 60 seconds.

Try DigitalOcean →

Get the daily digest

One email. 5 articles. Every morning.

No spam. Unsubscribe anytime.