The Azure Bring Your Own Key (BYOK) and Utimaco Enterprise Secure Key Manager (ESKM) integration enables customers to generate and manage encryption keys outside Microsoft Azure and securely import them into Azure Key Vault. This integration helps maintain customer control over encryption keys while using Azure services for data protection.
About This Guide
This document provides information on integrating Azure Bring Your Own Key (BYOK) with Utimaco Enterprise Secure Key Manager (ESKM). It explains the key concepts, prerequisites, and configuration steps required to manage encryption keys outside Azure using ESKM and securely import them into Azure Key Vault for use with Azure services.
Target Audience
This document is intended for Utimaco ESKM and Azure BYOK administrators.
Purpose of the Integration
The purpose of the Azure‑BYOK and Utimaco ESKM integration is to enable customers to generate and manage encryption keys outside Microsoft Azure while securely using those keys with Azure Key Vault. This integration helps customers retain control over key ownership and lifecycle management while meeting security and compliance requirements for protecting data in Azure.
Abbreviations
|
Abbreviation |
Meaning |
|---|---|
|
HSM |
Hardware Security Module |
|
Azure |
Microsoft Azure |
|
BYOK |
Bring Your Own Key |
|
ESKM |
Enterprise Secure Key Manager |
|
Key Vault |
Azure Key Vault |
|
API |
Application Programming Interface |
|
CMK |
Customer-Manager-Key |
Abbreviations
Document Conventions
The following conventions are used in this guide:
|
Convention |
Use |
Example |
|---|---|---|
|
Bold |
Items of the Graphical User Interface (GUI), e.g., menu options |
Select Details and click on Properties button |
|
|
Code that is given for explanation or as an example, file paths |
|
|
Italic |
References and important terms |
Operating system listed in Tested Versions |
Document conventions
We use special icons to highlight the most important notes and information.
Here you will find important safety information that should be followed.
Here you will find additional notes or supplementary information.
This message marks the result expected after the successful execution of an instruction.