Microsoft opened a public preview of Azure Payments HSM v2 this week, a managed, single-tenant hardware security module service built specifically for payment workloads: PIN processing, credential issuance, key management, and authentication data protection. The announcement is easy to skim past if you do not work in payments, but the architecture change from v1 is worth unpacking, because it signals where Azure wants to take dedicated security hardware in general.
What v2 changes
The first Payments HSM, generally available since November 2022, is BareMetal: customers get Thales payShield 10K appliances, certified to FIPS 140-2 Level 3 and PCI HSM v3, and they build their own high availability by provisioning pairs across stamps and standing up disaster recovery regions themselves. V2 is a different animal. Microsoft runs the availability and lifecycle of an isolated single-tenant cluster, there are no scheduled maintenance windows, and the customer keeps exclusive administrative control. Under the hood it is Marvell LiquidSecurity HSM hardware running Utimaco’s Atalla Payments Module software, which is one of the few payment stacks that runs across multiple hardware platforms. That matters for migration: shops running on-prem Atalla or payShield kit can test command compatibility before moving anything.
Certification moved up a level too. V2 targets FIPS 140-3 Level 3 and carries PCI DSS, PCI 3DS and PCI PIN validation on the underlying infrastructure. Microsoft’s key management guidance is explicit that the Payment HSM family is the only Azure key service with those payment certifications, so nothing else in the Key Vault, Managed HSM or Cloud HSM lineup substitutes for it.
Why payment networks force this
If you process PINs, you do not get to choose whether you need a certified HSM. The PCI PTS HSM standard defines the lifecycle security requirements, and it now covers multi-tenant HSMs in cloud environments, which is the regulatory change that makes a service like v2 possible at all. Visa’s PIN Security Program requires PCI-approved or FIPS 140-2 Level 3 or higher host security modules for PIN processing. One quirk of the single-tenant design: because each customer gets an isolated cluster, the service can be deployed as a validated component inside the customer’s own PCI solution rather than treated as shared provider infrastructure, which tends to simplify audits.
The networking model
V2 replaces v1’s delegated-subnet BareMetal attach with Azure Private Link. You create two private endpoints: a management port on 7005 for the Utimaco Secure Configuration Assistant and key loading device, and an application port on 2200 for Atalla payment commands, both fronted by a privatelink.phsm.azure.net private DNS zone and mutual TLS with self-signed EC P-256 root CAs. Public network access is disabled by default, and on-premises access runs over site-to-site or point-to-site VPN. Microsoft states it has no access to customer data or keys, and cluster release zeroizes everything.
Preview constraints to know before you get excited: only West US and West Europe, gated onboarding through a Microsoft account manager, and no charge during preview. GA pricing is undisclosed. Also, this is not fully self-serve yet. Onboarding requires a registered Utimaco account, which the docs warn can take up to 48 hours to activate, plus a physical welcome package with smart cards and a C3 Key Loading Device. Split-knowledge administration still means hardware ceremony and a courier, even in the cloud.
Getting into the preview
The mechanics of actually deploying one are worth counting before you plan around it. Start with the subscription work: get your account manager or Microsoft support to register you for the gated preview, activate a Utimaco support account, and register the AllowPrivateEndpoints feature on Microsoft.Network for each subscription that will host private endpoints. Then the network build-out: separate resource groups for the HSM cluster and the client workloads, two private endpoints (7005 management, 2200 application), the privatelink DNS zone association, NSG outbound rules for those endpoints, and a pair of self-signed EC P-256 root CAs for the mutual TLS trust. Admin access needs a jump box with SSH port forwarding or a VPN path, since there is no public endpoint to SSH into. And the onboarding does not complete until the physical welcome package arrives: the Secure Configuration Assistant workstation, the C3 Key Loading Device, and the smart cards for split knowledge. Budget weeks, not hours, for the first deployment, and treat the free preview as the window to learn the ceremony before GA pricing exists.
Where it fits in the Azure HSM lineup
Microsoft now sells four distinct options and the boundaries matter. Key Vault and Managed HSM handle cloud key management for ordinary applications. Azure Cloud HSM is the single-tenant general-purpose FIPS 140-3 Level 3 service for PKCS#11, JCE and CNG workloads. Azure Dedicated HSM is the legacy general-purpose BareMetal service, and Azure Payment HSM (both versions) is the payment-specific tier. If your workload is not payment-adjacent, none of this is for you, and spinning up a Payments HSM for general crypto would be an expensive way to satisfy an auditor.
For teams currently running v1 payShield pairs: v1 remains available in eight regions and the two services coexist, so there is no forced migration. The pragmatic move is to evaluate v2’s Atalla compatibility with your existing command set while keeping v1 in production, and to wait for GA pricing before committing any capacity plan to it. If your compliance roadmap includes PIN acceptance and your HSM estate is aging on-prem hardware, this preview is the first managed option on Azure that carries the full payment certification set without you operating the failover yourself.