Microsoft Expands Azure Key Vault Managed HSM with External Key Management Public Preview to Enhance Data Sovereignty for Regulated Industries

Microsoft has officially launched the public preview of external key management for its Azure Key Vault Managed Hardware Security Module (HSM), marking a significant milestone in the company’s multi-year roadmap to provide advanced data sovereignty solutions for global enterprises. This new capability addresses a critical requirement for organizations in highly regulated sectors, allowing them to maintain cryptographic keys on hardware that resides physically outside of Azure datacenters. By bridging the gap between cloud-scale computing and on-premises control, Microsoft is delivering on a commitment made a year ago to empower organizations with stringent jurisdictional and contractual obligations.
The introduction of external key management represents a strategic evolution of the Azure Key Vault Managed HSM service. Traditionally, Managed HSM has offered a single-tenant, high-security environment where keys are generated and stored within FIPS 140-3 Level 3 validated hardware. While this model provides robust isolation—ensuring that Microsoft operators have no access to plaintext key material—certain regulatory frameworks, particularly within the European Union and the financial services industry, demand that the "root of trust" remain entirely within the customer’s physical possession.
The Architectural Foundation of Managed HSM Sovereignty
To understand the impact of external key management, it is necessary to examine the existing security architecture of the Azure Key Vault Managed HSM. The service is built upon a dedicated cluster of HSM partitions, utilizing Marvell LiquidSecurity adapters. This single-tenant approach ensures that each customer has a dedicated cryptographic boundary. Unlike multi-tenant cloud services, where resources are shared, Managed HSM provides a hardware-level guarantee of isolation.
The sovereignty provided by Managed HSM is further reinforced by the integration of confidential computing technologies. By leveraging Intel SGX (Software Guard Extensions), Microsoft isolates request handling and access control within hardware-protected enclaves. These enclaves ensure that even an administrator with physical access to the host server cannot intercept the data or the keys being processed. For the vast majority of organizations, including those handling sensitive healthcare or financial data, this level of security exceeds traditional on-premises capabilities while maintaining the high availability and low latency expected of cloud services.
However, as data privacy laws like the General Data Protection Regulation (GDPR) and the Digital Operational Resilience Act (DORA) continue to evolve, the definition of "control" has become more granular. For some, control is not just about who can access the key, but where the physical silicon containing that key is located geographically and legally.
Defining the Scope of External Key Management
External key management for Managed HSM allows cryptographic operations within the Azure ecosystem to invoke key material stored on an HSM that the customer owns and operates, either in their own datacenter or through a third-party co-location provider. This is often referred to in the industry as "Hold Your Own Key" (HYOK), a step beyond the more common "Bring Your Own Key" (BYOK) model.
In a BYOK scenario, a customer generates a key locally and imports it into the cloud HSM. Once imported, the key resides within the cloud provider’s infrastructure, even if it remains inaccessible to the provider. In the newly announced external key management model, the key material never enters Microsoft’s infrastructure. Instead, the Managed HSM acts as a secure gateway, routing cryptographic requests to an external integration proxy that communicates with the customer’s on-premises HSM.
This model provides an ultimate "kill switch" for data access. Because the cryptographic operations require the external HSM to function, an organization can instantly revoke Azure’s ability to decrypt data by simply disconnecting their local hardware or shutting down the integration proxy. This level of physical and operational autonomy is designed specifically for scenarios where sovereign control is a non-negotiable legal requirement.
A Chronology of Commitment to Sovereign Solutions
The release of external key management in public preview is the culmination of a broader strategic initiative by Microsoft to address the "sovereign cloud" market. The timeline of this development reflects the increasing pressure from international regulators on cloud service providers.
In June 2023, Microsoft announced a comprehensive suite of sovereign solutions aimed specifically at European organizations. This announcement was a response to the "Schrems II" ruling and subsequent debates regarding the Cloud Act and its implications for European data privacy. At that time, Microsoft pledged to enhance its Azure Sovereign Cloud offerings by providing more transparency and greater control over data residency and encryption.
Throughout late 2023 and early 2024, Microsoft worked closely with various European regulatory bodies and financial institutions to refine the technical requirements for external key management. The goal was to create a solution that did not compromise the performance of Azure services while satisfying the "local control" mandates. The move to public preview in mid-2024 signifies that the technology has reached a level of maturity suitable for broader testing by enterprise customers.
Technical Mechanics and the HSM Ecosystem
The external key management feature operates through a dedicated API endpoint within the Managed HSM service. This endpoint facilitates communication with an external integration proxy. Microsoft does not provide or operate this proxy; instead, it relies on an open model that encourages a diverse ecosystem of hardware vendors.
Current and emerging partners in the HSM space, including industry leaders such as Thales, Entrust, and Fortanix, are actively working to ensure their platforms are compatible with the Managed HSM external key management API. This open approach allows organizations to leverage their existing investments in on-premises hardware. Customers have the choice of using vendor-provided implementations, partnering with a managed service provider, or building their own custom integration proxy to suit specific internal protocols.
One of the key technical advantages of this implementation is that it remains transparent to the application layer. Applications designed to work with Azure Key Vault do not need to be rewritten to support external keys. The Managed HSM handles the complex routing and handshaking required to fetch the cryptographic result from the external hardware, maintaining a consistent experience for developers.
Analyzing the Trade-offs: Control vs. Responsibility
While external key management provides unparalleled sovereignty, Microsoft is clear in its guidance that this model introduces significant operational responsibilities and potential risks. The shift of the "root of trust" to the customer means that the customer is now responsible for the availability and performance of the cryptographic backbone.
One of the primary considerations is latency. Because every cryptographic operation requires a network round-trip to the external HSM, the geographic distance between the Azure datacenter and the customer’s hardware becomes a critical factor. For high-throughput applications, such as real-time database encryption, the added latency of an external key can lead to degraded performance.
Furthermore, the burden of high availability shifts to the organization. If the on-premises HSM goes offline or the integration proxy fails, all Azure services relying on those keys will immediately lose access to the encrypted data. This requires organizations to maintain highly redundant power, cooling, and networking for their local HSM clusters—tasks that are typically handled by Microsoft within the Azure environment.
Security experts suggest that for the majority of workloads, the standard Managed HSM remains the superior choice. The native service provides FIPS 140-3 Level 3 security with the benefit of Azure’s global scale and 99.99% availability SLAs. External key management should be viewed not as a way to increase "baseline security," but as a specific compliance tool to meet regional or industry-specific regulatory hurdles.
Market Implications and Global Regulatory Context
The launch of this feature places Microsoft in a competitive position alongside other major cloud providers like Amazon Web Services (AWS) and Google Cloud Platform (GCP), both of which offer similar external key management solutions (such as AWS KMS External Key Store and Google Cloud External Key Manager).
The move is particularly relevant in the context of the EU-U.S. Data Privacy Framework. While the framework provides a legal basis for data transfers, many European organizations remain cautious. By offering a technical solution that keeps keys outside of U.S. jurisdiction, Microsoft is providing a "belt and braces" approach to compliance.
In the financial sector, the upcoming implementation of DORA in January 2025 is driving firms to re-evaluate their digital operational resilience. The ability to maintain physical control over encryption keys is seen as a vital component of a firm’s exit strategy and its ability to maintain operations independently of a single cloud provider’s infrastructure.
Public Preview Scope and Future Outlook
The public preview of external key management is currently available in a selection of major global regions, including East US, West US, North Europe, and West Europe. This geographical focus aligns with the areas of highest demand for sovereign cloud solutions. During this preview phase, Microsoft is actively seeking feedback from early adopters to refine the operational guidance and prioritize future vendor integrations.
As the service moves toward General Availability (GA), Microsoft is expected to expand the regional footprint and provide more detailed reference architectures for various industry use cases. The company has indicated that customer feedback during the preview will directly influence the development of the service’s final features, including enhanced monitoring and diagnostic tools for the integration proxy.
In conclusion, the introduction of external key management for Azure Key Vault Managed HSM represents a sophisticated response to the complex landscape of modern data sovereignty. By allowing customers to retain physical control over their cryptographic keys, Microsoft is removing one of the last significant barriers to cloud adoption for the world’s most highly regulated organizations. While the model requires a higher degree of operational maturity from the customer, it provides a definitive solution for those who must balance the power of the cloud with the strict requirements of national and industry mandates.







