Skip to content
Search Sign in List your company

Azure Cloud HSM

by Microsoft Azure from Microsoft

Page last updated
3 September 2026
What these mean

Report a problem with this product

Price on request

Azure Cloud HSM is Microsoft's single-tenant managed hardware security module service for organizations that need customer administrative control of HSMs while Azure manages cluster availability, patching and maintenance.

About Azure Cloud HSM

Azure Cloud HSM is a Microsoft Azure service for organizations that need a single-tenant hardware security module environment while retaining administrative authority over the HSMs. It is designed for demanding cryptographic workloads such as PKCS#11 applications, TLS key protection, certificate authority private keys, database encryption, and document or code signing. Cloud HSM provides a managed three-node HSM cluster so Microsoft handles infrastructure availability, patching, and maintenance while the customer controls cryptographic administration. Microsoft documents Azure Cloud HSM as the generally available successor option for Azure Dedicated HSM workloads.

What is included

Security

Tenant model Single-tenant HSM cluster dedicated to one customer
Validation FIPS 140-3 Level 3 validated hardware

Availability

Cluster architecture Three load-balanced HSM partitions per Cloud HSM instance

Operations

Infrastructure management Azure manages high availability, patching, and maintenance

Integration

Cryptographic interfaces PKCS#11, OpenSSL, JCA, JCE, CNG, and KSP are documented by Microsoft

Capacity

Key handles Up to 3,200 key handles per Cloud HSM instance

Networking

Production connectivity Microsoft strongly recommends private endpoints for production deployments

Pricing

Billing model Hourly billing per HSM cluster beginning at resource creation

Positioning

Migration role Generally available successor option for Azure Dedicated HSM workloads

What is Azure Cloud HSM used for?

Azure Cloud HSM is aimed at workloads that need direct access to dedicated hardware security modules and industry-standard cryptographic interfaces. Microsoft documents use cases including PKCS#11 applications, SSL and TLS offloading, certificate authority private-key protection, transparent data encryption, and document or code signing. It is particularly relevant when an organization is moving an application from on-premises HSM infrastructure, Azure Dedicated HSM, or AWS CloudHSM and wants to preserve an HSM-oriented architecture.

This is a specialized infrastructure security service rather than a general secret store. Applications still need to integrate with the HSM through supported cryptographic interfaces and teams remain responsible for how their keys and applications are administered.

How does the managed HSM cluster work?

Microsoft provisions each Azure Cloud HSM instance as three load-balanced HSM partitions in a highly available cluster. The service can balance cryptographic operations across the cluster and manages infrastructure availability, patching, and maintenance while the customer keeps administrative authority over the HSM environment. Periodic backups are also part of the service design.

The operational model is an important difference from older Dedicated HSM deployments. Customers still own cryptographic administration, user roles, key lifecycle decisions, and application integration, but Azure manages more of the underlying HSM infrastructure.

What security and compliance capabilities does Azure Cloud HSM provide?

Microsoft documents Azure Cloud HSM as a single-tenant service using FIPS 140-3 Level 3 validated hardware. Each instance is dedicated to one customer and uses a customer-specific security domain for cryptographic isolation. Microsoft also states that Cloud HSM keeps customer data within the Azure region where the instance is deployed.

Microsoft also documents support for compliance requirements including eIDAS and PCI or PCI 3DS scenarios. Organizations should still map the service to their own regulatory obligations, key-management procedures, separation-of-duties requirements, incident response process, and application security architecture rather than treating an HSM certification as complete compliance on its own.

Which applications and cryptographic interfaces can use Cloud HSM?

Microsoft documents Azure Cloud HSM support for PKCS#11, OpenSSL, Java Cryptography Architecture, Java Cryptography Extension, Cryptography API Next Generation, and key storage provider integrations. Documented workload examples include Active Directory Certificate Services, Apache or NGINX TLS offloading, F5 BIG-IP, SQL Server or Oracle transparent data encryption, and signing workloads.

That flexibility also means implementation effort depends heavily on the application. Teams should confirm that their software, cryptographic library, operating environment, and deployment architecture support the relevant interface before selecting Cloud HSM.

How is Azure Cloud HSM different from Azure Dedicated HSM?

Azure Cloud HSM is Microsoft's generally available successor option for Azure Dedicated HSM. Microsoft states that Azure Dedicated HSM retires on July 31, 2028, that existing customers remain supported until then, and that no new Dedicated HSM customer onboarding is accepted.

Microsoft's migration guidance also warns that customers cannot migrate existing key material directly from the Thales Luna Dedicated HSM environment to Azure Cloud HSM or Managed HSM because of source-HSM restrictions. A transition therefore requires new keys and application updates rather than an in-place key transfer.

How is Azure Cloud HSM different from Key Vault Managed HSM?

Cloud HSM is most relevant when applications need direct HSM-style integration and customer administrative control of a single-tenant HSM cluster. Microsoft positions Cloud HSM for applications that use industry-standard cryptographic interfaces and for migrations from traditional HSM environments.

Azure Key Vault and Managed HSM fit differently. They are designed around Azure key-management workflows and integrations. Buyers should start from application integration, compliance, operational control, and platform-integration requirements rather than assuming the service with the most direct hardware control is automatically the strongest choice.

What service limits should buyers review?

Microsoft's current service-limits documentation states that an Azure Cloud HSM instance supports up to 3,200 key handles regardless of key type and size. The documented maximum is 1,600 RSA keys, 1,600 elliptic-curve keys, or 3,200 AES keys when considered by type because RSA and EC keys consume two handles while AES keys consume one.

Transaction throughput also varies by cryptographic operation and key size. Microsoft publishes per-operation limits and notes that each instance contains three load-balanced HSM partitions. Large or latency-sensitive cryptographic workloads should therefore be capacity-tested against the current service-limits table rather than assuming every algorithm will deliver the same throughput.

How does Azure Cloud HSM pricing work?

Pricing was checked on September 3, 2026. Microsoft currently bills Azure Cloud HSM by HSM cluster on an hourly basis. Billing begins when the resource is created rather than when it is activated, and Microsoft states that the service cannot be paused or stopped to suspend charges. Deleting the resource is what ends billing.

Microsoft's public pricing page uses region and agreement-specific pricing and warns that displayed prices are estimates rather than contractual quotes. Buyers should use the current Azure pricing page or pricing calculator for their deployment region and agreement instead of relying on a static monthly figure. Network, virtual machine, application, storage, and other surrounding Azure resources can add separate costs.

What should buyers plan before deploying Azure Cloud HSM?

Cloud HSM should be treated as part of a wider cryptographic architecture. Teams need to plan network connectivity, application integration, administrative roles, key lifecycle procedures, backup and recovery, monitoring, regional deployment, and disaster recovery. Microsoft strongly recommends private endpoints for production deployments so Cloud HSM traffic stays on the Microsoft backbone rather than being exposed to the public internet.

Because billing starts at resource creation, deployment timing matters during testing and migration. Organizations transitioning from another HSM should test application compatibility, user administration, backup and restore, and key-rotation procedures before production cutover.

Who should choose something else?

Organizations that primarily need application secrets, certificates, or customer-managed keys for Azure platform services should compare Azure Key Vault and Azure Key Vault Managed HSM before adopting Cloud HSM. Cloud HSM is not a general secret store, and buyers whose workloads are built around Azure platform key integrations may not need direct HSM-style application interfaces.

Teams without a requirement for single-tenant HSM infrastructure or direct cryptographic interfaces may also find Cloud HSM unnecessarily specialized. Azure Cloud HSM is strongest when regulatory, application, or migration requirements genuinely call for a customer-controlled HSM cluster and the organization has the skills and processes to manage cryptographic administration.

Reviews

No reviews yet

Nobody has reviewed Azure Cloud HSM here yet.