Pool of FIPS-validated hardware security modules in Azure Key Vault, dedicated to a single tenant, able to store customer-managed encryption keys such as a TDE protector.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-700SC-500AI-103SC-900
Each book explains Managed HSM in context, with comparison tables and the common traps.
Terms in this definition
- Azure Key Vault
Azure service holding secrets, keys and certificates. If the region has a paired region in the same geography, contents replicate to it, and during a best-effort failover initiated by Microsoft the vault can only be read.
- Dedicated
Running Azure Functions on an App Service plan, which removes the execution time limit and offers VNet integration on Basic and higher tiers.
- Tenant
A trusted, dedicated Microsoft Entra ID instance that stores the users, groups and app registrations of one organisation. A subscription trusts only a single tenant, although a tenant can be trusted by several subscriptions.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- TDE protector
The key that encrypts (wraps) the TDE data encryption key: an asymmetric RSA key the customer manages and keeps in Key Vault or Managed HSM.
Related terms
- Customer-managed keys
RSA or RSA-HSM key of 2048, 3072 or 4096 bits that you keep in Key Vault or Managed HSM to wrap a storage account's encryption key. You can switch it on later, except for tables and queues, whose CMK support must be chosen at creation.
- Customer-managed keys (Azure AI Search)
Adds a further encryption layer to Azure AI Search, protecting indexes and synonym maps with an RSA key you hold in Key Vault or Managed HSM, which the service reaches using its managed identity. Expect queries up to 30-60% slower and no added capacity.
- Disk encryption set
Lets you choose your own key, held in Azure Key Vault or a Managed HSM, for the server-side encryption Azure applies to managed disks; each disk is pointed at this resource.
- HSM
A tamper-resistant hardware device that safeguards cryptographic keys; in Azure, Managed HSM and the RSA-HSM keys of Key Vault Premium use them.
- Microsoft-managed keys
The keys Azure uses by default to encrypt data at rest, which it creates, stores, rotates and backs up for you free of charge. If you must control the keys yourself, you use customer-managed keys held in Key Vault or Managed HSM instead.