HashiCorp Vault is Now a Supported Third-Party Integration with Azure Key Vault Managed HSM

The Azure Key Vault Managed HSM (Hardware Security Module) team is pleased to announce that HashiCorp Vault is now a supported third-party integration with Azure Key Vault Managed HSM. Hardware-backed keys stored in Managed HSM can now be used to automatically unseal a HashiCorp Vault. This offers customers the convenience of using a Microsoft Cloud key manager for automatic unsealing while keeping keys within a secure hardware boundary and Microsoft further out of the Trusted Computing Base.
“This integration with HashiCorp is emblematic of Microsoft’s mission to empower every person and every organization on the planet to achieve more,” says Eric Doerr, Corporate Vice President, Microsoft Cloud Security. “We’re thrilled to be able to offer hardware-backed key management via our Managed HSM offering to HashiCorp, harnessing confidential compute technologies to help customers protect their data.”
HashiCorp Vault is an identity-based security solution that leverages trusted sources of identity to keep secrets and application data secure, including API keys, passwords, or certificates. HashiCorp Vaults must be unsealed with an unsealing key to provide access to data. With this integration, customers can now use Managed HSM to reduce the operational overhead associated with storing and serving this unsealing key.
“Microsoft and HashiCorp have a shared vision on the importance of securing and automating a multi-cloud operating model,” says Burzin Patel, VP of Global Alliances at HashiCorp. “This new integration with Microsoft’s Azure Key Vault Managed HSM and HashiCorp Vault enables us to streamline secrets management workflows that are critical in a zero trust security environment.”
Microsoft announced the general availability of Azure Key Vault Managed HSM in June 2021 as part of its next generation of key management products. Managed HSM offers customers a single-tenant, FIPS 140-2 Level 3 validated, “HSM-as-a-Service” and uses Azure’s Confidential Compute infrastructure to take Microsoft further out of the Trusted Compute Base (TCB). This provides increased confidentiality and isolation to customer workloads. It’s all part of Microsoft’s broader goal to accelerate cloud adoption by making the cloud more trustworthy.
The team is looking forward to building on this vision and bringing more third-party integrations to Managed HSM in the future. HashiCorp’s integration with Azure Key Vault’s Managed HSM is now generally available and can be downloaded here.
For more information on:
- Azure Key Vault Managed HSM, visit https://aka.ms/mhsm
- HashiCorp Vault, visit https://www.hashicorp.com/products/vault
Published on:
Learn moreRelated posts
Azurite: Build Azure Queues and Functions Locally with C#
Lets say you are a beginner Microsoft Azure developer and you want to : Normally, these tasks require an Azure Subscription. But what if I tol...
Data encryption with customer-managed key (CMK) for Azure Cosmos DB for MongoDB vCore
Built-in security for every configuration Azure Cosmos DB for MongoDB vCore is designed with security as a foundational principle. Regardless ...
Azure Developer CLI: From Dev to Prod with Azure DevOps Pipelines
Building on our previous post about implementing dev-to-prod promotion with GitHub Actions, this follow-up demonstrates the same “build ...
Azure DevOps OAuth Client Secrets Now Shown Only Once
We’re making an important change to how Azure DevOps displays OAuth client secrets to align with industry best practices and improve our overa...
Azure Managed Instance for Apache Cassandra v5.0 Generally Available!
Azure Managed Instance for Apache Cassandra Upgrade to Cassandra v5.0 is now generally available, bringing a host of powerful new features and...
Hunting Living Secrets: Secret Validity Checks Arrive in GitHub Advanced Security for Azure DevOps
If you’ve ever waded through a swamp of secret scanning alerts wondering, “Which of these are actually dangerous right now?”— this enhancement...
Real-Time Security with Continuous Access Evaluation (CAE) comes to Azure DevOps
We’re thrilled to announce that Continuous Access Evaluation (CAE) is now supported on Azure DevOps, bringing a new level of near real-time se...