Key Vault Managed HSM naming convention
The CAF abbreviation for Key Vault Managed HSM is kvmhsm.
Names can be 3 to 24 characters long and allow alphanumerics and hyphens.
The name must be globally unique across all of Azure.
Naming rules
| CAF abbreviation | kvmhsm |
|---|---|
| Length | 3 to 24 characters |
| Allowed characters | Alphanumerics (a-z, A-Z, 0-9), hyphens |
| Scope of uniqueness | Global (must be unique across all of Azure) |
| CAF pattern | kvmhsm-{workload}-{environment}-{region}-{instance} |
Rules follow Microsoft's resource naming rules and CAF abbreviations. Some resource types have extra start/end character restrictions, so verify against the official docs before locking in a convention.
Naming Security resources
Key Vault has its own guide covering its strict 24 character global uniqueness and soft delete name reservation. Managed identities are cheap to create and usually provisioned per app or per function rather than shared, so unlike most of this list, their naming should tie tightly to the specific workload they are attached to.
VPN Gateway and Bastion resources are typically one per hub or region rather than one per environment, name them for the network boundary they protect. The common mistake is naming managed identities generically, id-prod for example, when dozens end up in the same subscription and it becomes impossible to tell which resource an identity actually belongs to.
Example names
Generated by the same engine as the name generator, so length and character rules are already applied.
| Scenario | Generated name | Length |
|---|---|---|
| Payments API, production | kvmhsm-payments-prod-001 Dropped region to fit the 24-char limit. | 24/24 |
| Web app, development | kvmhsm-webapp-dev-002 Dropped region to fit the 24-char limit. | 21/24 |
| Analytics with company prefix | kvmhsm-analyti-stage-001 Dropped company, region and shortened workload to fit 24 chars. | 24/24 |
Naming in Terraform and Bicep
Build the name from variables so one module produces the right name in every environment. The 24-character limit is enforced in the expression.
locals {
managed_hsm_name = substr("kvmhsm-${var.workload}-${var.environment}-${var.region}-001", 0, 24)
} var managedHsmName = take('kvmhsm-${workload}-${environment}-${region}-001', 24) Generate Key Vault Managed HSM names for your workload
Free, no login. Validation and Terraform, Bicep, or CSV export included.
Open in the generator →Related Security resources
See the full list of Azure resource naming rules or read the complete CAF naming guide.