Microsoft
At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.
We do business in 170 countries and are made up of 114,000 passionate employees dedicated to fulfilling our mission of helping you and your organization achieve more.
Detailed information about Entrust and Microsoft strategic partnership, including technical documentation and information on integrations can be found here in Entrust PKI, Entrust Identity, and Entrust BYOK.
Entrust is an official member of the Microsoft Intelligent Security Association.
Solution Description
Bringing the Entrust portfolio of trusted identity solutions to Microsoft customers enables secure connections between people, systems, and devices to streamline IT deployment, mitigate risk, and reduce fraud. Together, we enable even higher levels of growth and innovation. Entrust is an official member of the Microsoft Intelligent Security Association.
Entrust nShield HSMs safeguard the certificate issuance, management, and validation processes for organizations looking to extend the security of Microsoft Active Directory Certificate Services (AD CS) PKI. Using nShield hardware security modules (HSMs), all key generation and certificate signing operations are executed within the tamper-resistant confines of the module. Private keys are securely stored and never accessible outside the HSM. Microsoft published guidance on securing PKI:
- “Protecting CA Keys and Critical Artifacts” states that using an HSM is one of the strongest controls one can implement to provide strong protection of CA and other high-value keys.
Entrust nShield HSMs create tight controls around the management and the keys used to protect sensitive data at rest and in use across Azure-based on-premises and client applications. Microsoft Azure Key Vault safeguards the critical cryptographic keys used in the cloud to keep data secured. Used with Microsoft Azure Information Protection (AIP), the data exchanged within collaborative work environments is protected by embedding enforceable security policies right on the data assets, regardless of the data type.
Entrust key management for Microsoft SQL Server extends and enhances security by providing protection and lifecycle management for database encryption keys. Entrust nShield HSMs utilize Microsoft’s Extensible Key Management (EKM) interface to support transparent data encryption (TDE) and cell-level encryption modes for protection and consolidation of database application keys. This provides high assurance key archival for long-term data access and facilitates periodic rotation of encryption keys as required by regulations such as PCI DSS.
In addition to the resources below, several detailed integration guides are available for Entrust-Microsoft solutions. Please visit our Document Library for a full listing.
Documentation
Talk to an expert
Our experts will contact you to discuss how our partnerships and solutions can meet your needs.