Azure Key Vault Managed HSM – FIPS 140‑2 Level 3 Hardware Security for Compliance‑Heavy Workloads
Discover how Azure Key Vault Managed HSM delivers FIPS 140‑2 Level 3 validated hardware security, how to spin up an instance, generate keys, and integrate with Azure Functions. We also cover cost, region limits, and the lack of soft‑delete, giving you a clear decision framework.
19 Jan 2026, 21:28 UTC

Problem: Software‑Only Key Vault Can’t Meet FIPS 140‑2 Level 3
Many regulated industries (finance, healthcare, defense) require that cryptographic keys be protected by hardware security modules (HSMs) validated to FIPS 140‑2 Level 3. Azure Key Vault’s default SKU is software‑based and does not satisfy this requirement. Teams must decide whether to move to a dedicated HSM, weigh the cost and regional constraints, and integrate the new key store into their existing workloads.
Thesis: Managed HSM gives you the same Key Vault API, but in a dedicated, FIPS‑140‑2 Level 3 HSM, with a clear trade‑off curve.
1. Why Managed HSM?
- Hardware‑backed keys: RSA, EC, AES, and HMAC keys stored in dedicated HSM hardware.
- Full Key Vault API: create, import, wrap, unwrap, sign, verify, and delete keys via REST or SDK.
- Zero‑trust integration: Azure services (App Service, Functions, VMs) can access keys through managed identities without storing secrets.
- Scalable: up to 25,000 keys per instance, 5,000 ops/sec, elastic scaling via portal or CLI.
- Compliance: FIPS 140‑2 Level 3 badge visible in the portal.
2. Setting Up an Instance and Generating a Key
All commands run from an Azure‑CLI session with az login and az account set --subscription . The user must have Microsoft.KeyVault/managedHSMs/write and Microsoft.KeyVault/managedHSMs/read permissions.
# Create a resource group
az group create --name myHSMRG --location eastus
# Create a Managed HSM instance (free tier – 1 instance, 1,000 keys)
az keyvault managed-hsm create \
--name myManagedHSM \
--resource-group myHSMRG \
--location eastus \
--sku standard
# Verify the FIPS badge (UI only, but you can check the SKU name)
az keyvault managed-hsm show --name myManagedHSM --query sku.name
# Generate an RSA key (2048‑bit) via CLI
az keyvault key create \
--vault-name myManagedHSM \
--name myRSAKey \
--kty RSA \
--size 2048
# Export the public key (used for verification)
az keyvault key download \
--vault-name myManagedHSM \
--name myRSAKey \
--file myRSAKey.pub
Expected checks:
- Command exits with
200 OKstatus. - Public key file contains a PEM‑encoded RSA public key.
- Key metadata shows
kty: RSAandkey_size: 2048.
3. Integrate with an Azure Function via Managed Identity
Assume you have a Function App named hsmSignFunction. The function will sign a payload using the HSM key.
- Enable a system‑assigned managed identity on the Function App via the portal or CLI:
az functionapp identity assign \
--name hsmSignFunction \
--resource-group myHSMRG
- Grant the Function App’s identity
keyvault/keys/operationson the Managed HSM:
az keyvault key set-policy \
--vault-name myManagedHSM \
--name myRSAKey \
--object-id $(az functionapp identity show \
--name hsmSignFunction \
--resource-group myHSMRG \
--query principalId -o tsv) \
--permissions sign verify
Risk note: Granting permissions only to the specific key limits blast radius. Avoid allPermissions unless absolutely necessary.
# Sample C# code inside the Function
using Azure.Identity;
using Azure.Security.KeyVault.Keys;
using Azure.Security.KeyVault.Keys.Cryptography;
var client = new CryptographyClient(
new Uri("https://myManagedHSM.vault.azure.net/keys/myRSAKey"),
new DefaultAzureCredential());
byte[] payload = Encoding.UTF8.GetBytes("Hello, HSM!");
SignResult result = await client.SignAsync(SignatureAlgorithm.RS256, payload);
// result.Signature can be returned to the caller
Verification: Use the exported public key to verify the signature with an external tool (openssl, Node.js crypto, etc.).
4. Monitoring and Scaling
Azure Monitor exposes metrics such as KeyOperationCount and KeyOperationLatency. You can set up alerts when operations approach the 5,000 ops/sec limit or when latency exceeds a threshold.
# Create a metric alert for high operation count
az monitor metrics alert create \
--name HSMHighOps \
--resource-group myHSMRG \
--scopes /subscriptions//resourceGroups/myHSMRG/providers/Microsoft.KeyVault/managedHSMs/myManagedHSM \
--condition "GreaterThan 4000" \
--window-size 5m \
--evaluation-frequency 1m \
--action-group myActionGroup
Scaling: If you hit the operation limit, you can add an instance via the portal or CLI and configure load balancing across instances. The portal UI shows a “Scale” button; the CLI command is az keyvault managed-hsm update --name myManagedHSM --sku standard --capacity .
5. Trade‑offs and Limitations
- Cost: Managed HSM instances are priced per hour (e.g., $0.50/hr for standard). The free tier is limited to one instance and 1,000 keys.
- Region Availability: Only a subset of Azure regions support Managed HSM. Check with
az keyvault managed-hsm list-locations. - No Soft‑Delete: Keys cannot be recovered after deletion; you must back up keys manually (e.g., export and store the key material).
- Limited Features: Some Key Vault capabilities (e.g., RSA‑OAEP‑256 wrapping, key rotation schedules) are not yet supported. Verify feature support in the latest docs.
- Cross‑Subscription Access: Managed HSM is tied to a single subscription; you cannot grant access from another subscription.
6. Actionable Checklist
- Verify your region supports Managed HSM (
az keyvault managed-hsm list-locations). - Plan key count and operation throughput; choose the appropriate SKU and number of instances.
- Back up critical keys: export and securely store the key material before deletion.
- Grant the minimal necessary permissions to services via managed identities.
- Set up Azure Monitor alerts for key operations and latency.
- Review cost impact in the Azure Cost Management dashboard.
By following this workflow, you can satisfy FIPS 140‑2 Level 3 compliance while keeping integration with your existing Azure services straightforward.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.