The keys used by Microsoft Cloud PKI are protected within Microsoft’s cloud infrastructure. A customer-owned HSM or third-party HSM cannot be used directly as the key store for a Microsoft-managed Cloud PKI CA.
For companies that need to retain control over key material and HSM infrastructure for regulatory, organizational, or security reasons, operating their own PKI or using a Managed PKI can therefore provide greater flexibility. MTG Corporate PKI supports both On-Premises and Managed Service deployment models.