Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Note
Zero Trust is a security strategy comprising three principles: "Verify explicitly", "Use least privilege access", and "Assume breach". Data protection, including key management, supports the "use least privilege access" principle. For more information, see What is Zero Trust?
Azure supports platform-managed and customer-managed encryption keys.
Azure generates, stores, and manages platform-managed keys (PMKs). You don't need to interact with PMKs. For example, the keys used for Azure Data Encryption at Rest are PMKs by default.
Customer-managed keys (CMKs) are keys that you create, delete, use, and manage. You can store CMKs in a customer-owned key vault or hardware security module (HSM). Bring your own key (BYOK) is a CMK scenario where you import keys from an external storage location into an Azure key management service. For more information, see Azure Key Vault: Bring your own key specification.
A key encryption key (KEK) is a primary key that controls access to one or more encryption keys that it encrypts.
You can store CMKs on-premises or, more commonly, in a cloud key management service.
Azure key management services
Azure offers several options for storing and managing your keys in the cloud, including Azure Key Vault, Azure Key Vault Managed HSM. These options differ in their FIPS compliance level, management overhead, and intended applications.
Azure Key Vault (standard tier)
Azure Key Vault standard tier is a FIPS 140-2 Level 1 validated multitenant cloud key management service. You can use it to store asymmetric keys, secrets, and certificates. Keys stored in Azure Key Vault standard tier are software-protected. You can use them for encryption at rest and custom applications. Azure Key Vault standard tier provides a modern API and broad regional deployments and integrations with Azure services. For more information, see About Azure Key Vault.
Azure Key Vault (premium tier)
Azure Key Vault premium tier is a FIPS 140-3 Level 3 validated, PCI-compliant, multitenant HSM offering. Use it to store asymmetric keys, secrets, and certificates. It stores keys in a secure hardware boundary by using Marvell LiquidSecurity HSMs. Microsoft manages and operates the underlying HSM. Use keys stored in Azure Key Vault premium tier for encryption at rest and custom applications. Azure Key Vault premium tier also provides a modern API, broad regional deployments, and integrations with Azure services.
If you're an Azure Key Vault premium tier customer looking for key sovereignty, single tenancy, or higher crypto operations per second, consider Azure Key Vault Managed HSM instead. Key Vault premium tier uses shared HSMs operated by Microsoft. Use Managed HSM for workloads that require a customer-owned root of trust. For more information, see About Azure Key Vault.
Note
Azure Key Vault premium tier allows the creation of both software-protected and HSM-protected keys. If you use Azure Key Vault premium tier, verify that the key you create is HSM-protected.
Azure Key Vault Managed HSM
Azure Key Vault Managed HSM is a FIPS 140-3 Level 3 validated, single-tenant HSM offering that gives you full control of an HSM for encryption at rest, Keyless SSL/TLS offload, and custom applications. Azure Key Vault Managed HSM is the only key management solution offering confidential keys. You receive a pool of three HSM partitions that act as one logical, highly available HSM appliance. A service front-end exposes cryptographic functionality through the Key Vault API. Microsoft handles HSM provisioning, patching, maintenance, and hardware failover, but doesn't have access to the keys. The customer owns and controls the security domain, which is the root of trust for the HSM. Loss of the security domain results in permanent, irrecoverable loss of all keys. Azure Key Vault Managed HSM integrates with Azure SQL, Azure Storage, Azure Information Protection, and Customer Key for Microsoft 365. It also supports Keyless TLS with F5 and NGINX. For more information, see Azure Key Vault Managed HSM overview.
Pricing
Azure Key Vault standard and premium tiers bill on a transactional basis, with an extra monthly per-key charge for premium hardware-backed keys. Azure Key Vault Managed HSM doesn't charge on a transactional basis. Instead, they're always-on devices that bill at a fixed hourly rate. For detailed pricing information, see Key Vault pricing.
Service limits
Azure Key Vault Managed HSM offers dedicated capacity. Azure Key Vault standard and premium tiers are multitenant offerings and have throttling limits. For service limits, see Key Vault service limits.
Encryption at rest
Azure Key Vault and Azure Key Vault Managed HSM integrate with Azure services and Microsoft 365 for customer-managed keys. You can use your own keys in Azure Key Vault and Azure Key Vault Managed HSM for encryption at rest of data stored in these services. For an overview of encryption at rest with Azure Key Vault and Azure Key Vault Managed HSM, see Azure Data Encryption at Rest.
APIs
Azure Key Vault and Azure Key Vault Managed HSM don't support these APIs. Instead, they use the Azure Key Vault REST API and offer SDK support. For more information on the Azure Key Vault API, see Azure Key Vault REST API Reference.