Taking Control of Cloud Encryption: Entrust Supports External Key Management for Azure Key Vault Managed HSM

Sep

03

2026

Time to read

Read so far

Written by: 

Mike Baxter

Time to read

Written by: 

Digital key icon with glowing circuit lines, binary code, and cybersecurity graphics on a purple background

Entrust support for external key management in Microsoft Azure Key Vault Managed HSM helps organizations achieve a long-standing best practice in data security: keeping encryption keys under their own control and separate from the data they protect. This approach strengthens data sovereignty, improves resilience, and gives organizations greater governance over one of their most critical security assets.

Key Takeaways

  • External key management in Azure Key Vault Managed HSM enables customer-controlled encryption keys for specific sovereignty and compliance requirements
  • Hold Your Own Key (HYOK) models can help separate data and key custody where physical key-control requirements apply
  • Entrust combines external key management with nShield HSM-backed assurance
  • Organizations can strengthen governance while continuing cloud adoption

As organizations modernize across cloud and hybrid environments, data custody, resilience, and sovereignty have become central to the data protection conversation. Enterprises are under pressure to prove that sensitive data remains protected, recoverable, and under their control — even as it moves across infrastructure and service providers. The critical question is who controls the keys that protect your data?

For highly regulated and compliance-driven sectors, cryptographic key control is increasingly central to cloud strategy. It helps organizations align with evolving regulations and frameworks, including DORA and NIS 2 in Europe and U.S. SEC cybersecurity disclosure rules. It is also key to managing provider risk as workloads move to the cloud. By separating cryptographic control from the infrastructure platforms and providers that store or process sensitive data, organizations support data sovereignty requirements and maintain confidence that sensitive data remains protected.

That is why Entrust supports external key management in Azure Key Vault Managed HSM through the Entrust Cryptographic Security Platform Key Manager, backed by Entrust nShield Hardware Security Modules (HSMs). This new Managed HSM capability gives Azure customers with specific regulatory, contractual, or digital-sovereignty requirements an option for protecting data using customer-managed keys, while authority over the key management infrastructure used to secure those keys remains solely with the customer.

External key management is a Hold Your Own Key, or HYOK, model. This means that the customer maintains control of the cryptographic keys used to protect cloud data, using key management infrastructure they own, operate, or physically control. For organizations with strict sovereignty, privacy, compliance, or operational separation requirements, the HYOK model can provide additional assurance where physical control of key material outside the cloud provider’s environment is required. As cloud adoption expands, organizations need security models that support innovation without weakening governance. Data sovereignty is now about more than where data resides. It is also about who can access it, how it is protected, which jurisdictions may influence its handling, and whether the organization can provide clear evidence of control to auditors, regulators, boards, customers, and partners.

How External Key Management for Azure Key Vault Managed HSM Works with Entrust

External key management in Azure Key Vault Managed HSM lets organizations keep the Key Encryption Key (KEK) in customer-owned, customer-operated HSM infrastructure outside Microsoft infrastructure, while Managed HSM delegates wrap and unwrap operations through a customer-run EKM Proxy. Entrust leverages this model by enabling customers to use Entrust Cryptographic Security Platform Key Manager as the external key management capability, with nShield HSMs providing a certified, hardware-rooted foundation for high-assurance key protection. This model shifts responsibility for the external HSM, proxy, networking, availability, and support to the customer or their HSM vendor.

This is particularly relevant for organizations that want physical control over the keys that protect sensitive data while continuing to take advantage of cloud services. These models can support broader risk, sovereignty, and compliance strategies by aligning cryptographic control with business accountability.

Centralized Key Control

Entrust Cryptographic Security Platform Key Manager also helps organizations centralize key lifecycle management and policy control across distributed environments. When backed by Entrust nShield HSMs, customers can add hardened, tamper-resistant hardware protection for critical keys and cryptographic operations. Together, these capabilities help organizations strengthen trust in their cloud security models while supporting the operational requirements of hybrid and multi-cloud environments.

This support builds on the long-standing relationship Entrust has with Microsoft across trusted encryption, digital signing, key protection, and data security use cases. More broadly, the Entrust Cryptographic Security Platform has been recognized as a cryptography posture management provider with deep connections to the Microsoft Security ecosystem, reflecting Entrust’s role in helping organizations improve visibility, governance, and control across their cryptographic estates.

Beyond Key Custody: Addressing Fragmented Cryptographic Estates

External key management is an important step, but key custody is only one part of the broader cryptographic security challenge. Many organizations operate fragmented cryptographic estates, where keys, certificates, secrets, and policies are spread across teams, applications, infrastructure, and cloud platforms. This fragmentation can create blind spots, increase operational risk, and make it harder to demonstrate compliance.

Entrust helps customers address this challenge through its Cryptographic Security Platform ecosystem, supporting discovery, visibility, policy enforcement, lifecycle management, compliance reporting, and centralized control across cryptographic assets. This helps security, compliance, and risk leaders better understand where cryptography is being used, how keys are managed, and where governance or protection can be strengthened.

For C-level leaders, the value is increased confidence that:

  • cloud adoption can continue without surrendering key control
  • regulatory and sovereignty requirements can be addressed with clear evidence
  • cryptographic operations are governed consistently across complex environments
  • the organization is better prepared for future changes in compliance, technology, and risk

What This Means for the Enterprise

Entrust has a strong track record of collaboration with Microsoft across identity, PKI, HSM, key management, and data protection use cases. Entrust capabilities support Microsoft Entra Verified ID, Microsoft Entra ID, Microsoft Active Directory Certificate Services, Microsoft Purview Double Key Encryption, Microsoft Azure Key Vault, Microsoft SQL Server, Microsoft Intune and other Microsoft environments. Entrust is also a member of the Microsoft Intelligent Security Association (MISA).

With support for external key management in Azure Key Vault Managed HSM, Entrust helps customers take the next step in cloud trust, resilience, and data sovereignty. By combining Azure innovation with Entrust external key management capabilities and nShield HSM-backed assurance, organizations can retain authority over the keys that protect their most sensitive data while moving forward with confidence in the cloud.

External key management in Azure Key Vault Managed HSM is now available in public preview. Entrust Cryptographic Security Platform Key Manager support is planned for September 2026.

Related Links:

Mike Baxter headshot
Mike Baxter
President and Chief Technology & Product Officer

Mike Baxter leads all Entrust product management and development teams across its issuance, identity security, and data security solutions. He applies a deep knowledge of AI and post-quantum security to the company’s technology and platform strategy to anticipate future customer use cases.

Dr. Baxter has been part of the Entrust leadership team since 2010. Previously he held the position of Vice President, Engineering and Operations for FSI International, a global provider of semiconductor processing equipment. He also held leadership positions in product development for the Solvay Group, both in Europe and the USA. Mr. Baxter holds a doctorate in Mechanical Engineering from Purdue University and a Bachelor of Science in Chemical Engineering from the University of Minnesota.

View all of Mike's Posts
Facebook