HYOK uses an isolated on-premises AD RMS instance that provides the RMS templates based on the second different private key that's driven by an AIP label. This deployment model should be chosen for high security and compliance requirements.
Most of the time, this us used for data that can't be stored on a public cloud. This sensitive data needs to be stored and protected on-premises. Keep in mind that HYOK-protected data is typically between 3 to 5% of an organization's protected data. The following diagram shows the deployment model:
The following limitations/benefits are available by design: