Overview of Azure Key Vault Managed HSM (HYOK)
Azure Key Vault Managed HSM (HYOK) allows organizations to protect highly sensitive data while keeping full control of their encryption keys. With External Key Management, encryption keys remain in the organization’s own environment and are not stored in the cloud.
Azure Information Protection is used for data classification and labeling, while encryption and key operations are performed using on‑premises Rights Management Services with customer‑controlled keys. This approach helps organizations meet security, compliance, and data ownership requirements without changing the user experience.
Overview of ESKM
Utimaco Enterprise Secure Key Manager (ESKM) is a solution used to securely manage encryption keys within an organization’s own environment. It helps create, store, and control encryption keys in a central and secure way.
ESKM works with Hardware Security Modules (HSMs) to protect keys and meet security and compliance requirements. In the Azure Key Vault Managed HSM (HYOK) integration, ESKM ensures that encryption keys remain fully under the organization’s control and are not stored or managed in the cloud.
Joint Value Proposition
This integration enables Azure Hold Your Own Key (HYOK) by allowing customers to keep their encryption keys outside Azure in a customer‑owned Hardware Security Module (HSM) or external key management system (ESKM).
Azure accesses these externally stored keys through ESKM to perform cryptographic operations for supported Azure services using Customer‑Managed Keys (CMK), while the key material remains entirely within the customer‑controlled environment and is never exposed to Azure.
Azure Key Vault Managed HSM (HYOK) creates the data encryption key (DEK) and securely sends it to ESKM. ESKM protects the DEK by encrypting it with a key that is created and stored only in ESKM. This key never leaves the customer’s environment.
Azure stores only the encrypted DEK and cannot access the data without the key held in ESKM. This ensures customers retain full control of their encryption keys while securely integrating with Azure services.