Utimaco Brings Sovereign Key Control in Microsoft Sentinel

Press Release Date: 11 Aug 2026 11 Aug 2026
Table of Contents

The new integration of Utimaco Enterprise Secure Key Manager in Microsoft Sentinel

Organizations are moving workloads to multi-cloud and multi-platform environments faster than ever. This shift delivers scale and flexibility, but it also raises a pressing question: Who really controls your data once it leaves your infrastructure?

The answer comes down to: The one who is in control over your encryption keys

Data sovereignty in the cloud depends on your ability to store, manage, and monitor cryptographic keys independently of the platforms that hold your data. Utimaco's Enterprise Secure Key Manager (ESKM) now integrates directly with Microsoft Sentinel to give security teams exactly that level of control and visibility.

 

The Data Sovereignty Challenge in Multi-Cloud Environments

Cloud adoption spreads sensitive data across decentralized, globally distributed, and heterogeneous systems. Each platform introduces its own access controls, logging formats, and compliance considerations. That fragmentation makes true sovereignty difficult to achieve.

Three challenges stand out for security and compliance teams:

  • Central access management — ensuring that only authorized users and entities can access protected data.
  • Compliance and security — meeting strict regulatory requirements across regions and platforms.
  • Strictest environment protection — maintaining centralized visibility over every cryptographic operation and request.

Without a unified approach to key management, encryption keys become scattered, monitoring stays reactive, and audit trails remain incomplete. Sovereignty requires that keys are held separately from encrypted data and that every key operation is visible to the teams responsible for protecting it.

 

Utimaco Effectively Addresses the Data Sovereignty Challenge 

How the integration of ESKM with Microsoft Sentinel works

Microsoft Sentinel provides an AI-ready platform that combines industry-leading SIEM capabilities, a unified data lake, graph-powered visibility, and intelligent reasoning tools. Its Codeless Connector Framework (CCF) lets Sentinel ingest data from external REST APIs - including the ESKM management API - into Log Analytics tables without custom code, using a polling-based RestApiPoller governed by a Data Collection Rule (DCR).

ESKM extends this platform by securely protecting and orchestrating all cryptographic keys across those distributed environments. The integration is straightforward for security operations teams:

  1. Install ESKM through the Sentinel Content Hub, which provisions the Data Collection Rule and RestApiPoller automatically.
  2. Pull KMIP logs from ESKM via polling
    The CCF RestApiPoller authenticates to the ESKM management API over HTTPS (basic auth) and pulls KMIP server logs every 5 minutes, normalizing them via the DCR into the UtimacoESKMKmipServerLogs_CL table.
  3. Detect and respond
    Scheduled analytic rules, four hunting queries, and the operational workbook consume that table to generate incidents, surface anomalies, and visualize KMIP activity.

By feeding KMIP server logs into Microsoft Sentinel, ESKM makes every key-related event available to the security operations team. This connects sovereign key management with a platform your analysts already use, without adding operational complexity.
 

Central Visibility Through a Single Pane of Glass

Once integrated, ESKM delivers a single pane of glass for cryptographic operations. Security teams gain complete visibility over every KMIP operation, authentication event, and state change within the Microsoft Sentinel environment.

An operational dashboard supports day-to-day monitoring of the KMIP plane. Instead of piecing together fragmented logs from multiple sources, analysts see key activity in one consolidated view. This unified perspective enables preventive measures, faster threat detection, and rapid incident response.

Central visibility is the foundation of sovereignty. When you can see every request for a key - who made it, when, and from where - you hold genuine control over your data.

 

Anomaly Detection and Proactive Threat Hunting

Visibility becomes powerful when paired with detection. The ESKM–Sentinel integration includes built-in detection logic that identifies the patterns most associated with key compromise and insider threats:

  • Brute-force authentication attempts against the key management layer
  • Privilege escalation probing by users testing their access boundaries
  • Mass key destruction, a strong indicator of ransomware or malicious activity

Beyond automated detection, the integration ships four pre-built KQL hunting queries analysts can run on demand: rare KMIP users (newly provisioned or unknown service accounts), new source IPs reaching the KMIP API, high-volume key retrievals, and after-hours activity. These signals often precede a security incident, so identifying them early allows teams to intervene before data is exposed.

This shift from reactive to proactive security is critical in distributed cloud environments, where the attack surface is broad and threats move quickly.

 

Key Benefits for Security and Compliance Teams

The integration strengthens both security and compliance posture in the Microsoft Cloud. The core benefits include:

  • Central key management and control 
    All cryptographic keys are stored centrally and accessible only to authorized users, enforcing operations such as rotation, exchange, and revocation.
  • Reliable data protection across platforms 
    Encryption keys are securely stored and strictly separated from the data they protect
  • Compliance fulfillment 
    Strict separation of keys and encrypted data, combined with audit logs, supports adherence to multiple laws and regulations
  • Transparent KMIP monitoring 
    Role-based access control, detailed audit logs, and a pre-built operational workbook (event volume over time, top users and source IPs, operation distribution and authentication trends) for complete operational visibility
  • Faster anomaly detection 
    Centralized insight enables preventive action and quicker incident response

Together, these capabilities give organizations the assurance that their keys — and therefore their data — remain under their sole control, regardless of where the data resides.

 

Why Full Key Control Matters for Data Sovereignty

A primary element of enabling digital sovereignty in the cloud is sovereign management of the keys used to protect data and encrypt cloud-stored information. When keys are managed separately from the cloud platform and monitored through a system you control, you retain authority over access and compliance.

The ESKM integration with Sentinel operationalizes this principle. It combines Sentinel's threat detection and analytics with ESKM's secure, centralized key management. 
The result is a security architecture where:

  • Keys are managed independently from the CSP environment
  • Every cryptographic operation is logged and auditable
  • Suspicious activity is detected and investigated in real time
  • Compliance requirements are met with verifiable evidence.

Corporate data protection strategies are adapting quickly to ensure trust, compliance, sovereignty, and control needed for operational resilience. 

This integration directly supports that goal, making key management more secure and compliance easier to achieve within the environments teams already rely on.


"Customers need strong security controls that help protect data without adding unnecessary complexity. By integrating Utimaco's Enterprise Secure Key Manager, organizations can separate encryption keys from the data they protect while maintaining centralized control of key management. This approach strengthens security, helps support data sovereignty requirements, and helps provide a trusted foundation for AI-ready workloads."
Jesse Kopavi, Principal Product Manager, Microsoft Security
 

Take Control of Your Keys and Your Data 

Sovereignty is not a feature you switch on — it is the outcome of controlling your keys, monitoring every operation, and meeting compliance obligations with confidence. The integration of Utimaco ESKM with Microsoft Sentinel gives your security operations team the visibility and control to achieve it.

Ready to bring sovereign key management to your cloud environment? 
Explore how our flagship product Enterprise Secure Key Manager, delivered as physical or virtual hardware supports your data sovereignty strategy. 
Based on its unique capability to manage more than 2 million keys and over 25,000 clients it helps you to protect, orchestrate, and monitor all your cryptographic keys across multi-cloud and multi-platform infrastructures through a single pane of glass.

With Enterprise Secure Key Manager as a Service we are providing key management as a cloud-based, fully managed service. 
Combining the capabilities of a Key Management System with those of a General Purpose Hardware Security Module it provides holistic crypto key generation, management and storage.

 

About the Author

David Phister

David Phister

Director Product Management, Utimaco

Prêt à assurer votre avenir numérique ?

Rejoignez plus de 500 entreprises mondiales et institutions gouvernementales qui font confiance à Utimaco pour leur infrastructure de sécurité critique.

Contacter le service des ventes

How can we help you?

Talk to one of our specialists and find out how Utimaco can support you today.
You have selected two different types of downloads, so you need to submit different forms which you can select via the two tabs.

Your download request(s):

    By submitting below form you will receive links for your selected downloads.
    Loading...

    Your download request(s):

      For this type of documents, your e-mail address needs to be verified. You will receive the links for your selected downloads via e-mail after submitting below form.
      Loading...

      About Utimaco's Downloads

      Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).

      For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.

      Download via e-mail

       

      A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.