A tamper-resistant hardware device that safeguards cryptographic keys; in Azure, Managed HSM and the RSA-HSM keys of Key Vault Premium use them.
Also called hardware security module.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305SC-500SC-900MD-102DP-800ALZ
Each book explains HSM in context, with comparison tables and the common traps.
Terms in this definition
- Managed HSM
Pool of FIPS-validated hardware security modules in Azure Key Vault, dedicated to a single tenant, able to store customer-managed encryption keys such as a TDE protector.
- Key Vault Premium
Tier of Key Vault offering HSM-protected RSA-HSM and EC-HSM keys in addition to the software-protected keys found in Standard. Rotation policies work on either tier.
Related terms
- Azure Dedicated HSM
Thales hardware security module dedicated to one tenant and placed in your own VNet; the service is being retired and takes no new customers.
- Key Vault Standard
Lower Key Vault tier, offering software-protected RSA and EC keys at FIPS 140 Level 1. Keys backed by an HSM require Premium, though key rotation policies are available on either tier.