Introduction

The Azure Bring Your Own Key (BYOK) and Utimaco Enterprise Secure Key Manager (ESKM) integration enables customers to generate and manage encryption keys outside Microsoft Azure and securely import them into Azure Key Vault. This integration helps maintain customer control over encryption keys while using Azure services for data protection.

About This Guide

This document provides information on integrating Azure Bring Your Own Key (BYOK) with Utimaco Enterprise Secure Key Manager (ESKM). It explains the key concepts, prerequisites, and configuration steps required to manage encryption keys outside Azure using ESKM and securely import them into Azure Key Vault for use with Azure services.

Target Audience

This document is intended for Utimaco ESKM and Azure BYOK administrators.

Purpose of the Integration

The purpose of the Azure‑BYOK and Utimaco ESKM integration is to enable customers to generate and manage encryption keys outside Microsoft Azure while securely using those keys with Azure Key Vault. This integration helps customers retain control over key ownership and lifecycle management while meeting security and compliance requirements for protecting data in Azure.

Abbreviations

Abbreviation

Meaning

HSM

Hardware Security Module

Azure

Microsoft Azure

BYOK

Bring Your Own Key

ESKM

Enterprise Secure Key Manager

Key Vault

Azure Key Vault

API

Application Programming Interface

CMK

Customer-Manager-Key

Abbreviations

Document Conventions

The following conventions are used in this guide:

Convention

Use

Example

Bold

Items of the Graphical User Interface (GUI), e.g., menu options

Select Details and click on Properties button

Monospaced

Code that is given for explanation or as an example, file paths

certreq.exe -new request.inf IISCertRequest.csr

Italic

References and important terms

Operating system listed in Tested Versions

Document conventions

We use special icons to highlight the most important notes and information.

Here you will find important safety information that should be followed.

Here you will find additional notes or supplementary information.

This message marks the result expected after the successful execution of an instruction.