Skip to main content
Cloud / Azure / Products / Azure Enclave - Isolated, Compliant Environments

Azure Enclave - Isolated, Compliant Environments

Azure Enclave (preview): accelerates building and running secure, isolated, compliant cloud environments through communities, enclaves, and workloads.

networking
Pricing Model Hourly billing per the official pricing page (Azure Virtual Enclaves)
Availability Preview; per Microsoft, certain features might not be available in all Azure locations
Data Sovereignty Designed for commercial and air-gapped environments; region and data handling per official documentation
Reliability No SLA - Azure Enclave is provided without a service-level agreement during preview SLA

What is Azure Enclave?

Azure Enclave accelerates and streamlines the deployment and management of secure, isolated, and compliant cloud environments for the most sensitive workloads. Per Microsoft, it is designed for commercial and air-gapped environments.

Important: Azure Enclave is currently in preview and is provided without a service-level agreement. Microsoft explicitly states that at this time Azure Enclave shouldn’t be used for production workloads. Certain features might not be supported, might have constrained capabilities, or might not be available in all Azure locations.

Azure Enclave takes a multi-layered and hierarchical approach to virtual boundary protection. A community serves as a central hub for networking, governance, and monitoring for a collection of isolated networks known as enclaves. Azure Enclave manages hub and firewall routing along with virtual network flow logging for configured enclave networking paths. Enclaves are isolated, zero-trust software-defined networks (Azure Virtual Network) that host your Azure service workloads. Enclaves and your workloads are governed through policy configuration management with Azure Policy.

Azure Enclave should not be confused with the hardware-based enclaves of confidential computing: Azure Enclave operates at the level of network isolation and governance.

Core Features

  • Communities as a managed virtual WAN boundary with Azure Firewall, policy guardrails, and RBAC deny assignments
  • Enclaves as isolated, managed virtual networks with network security groups and deny assignments
  • Workloads as logical groups whose resources inherit the enclave’s security posture, policies, and permissions
  • Connection management through enclave endpoints, community endpoints, transit hubs, and enclave connections
  • Azure Policy guardrails controlling which resource types and configurations are allowed
  • Logging and monitoring into a community or enclave Log Analytics workspace, depending on configuration
  • Access controls using Azure roles and deny assignments to prevent unauthorized changes to managed resources
  • Service catalog with validated deployment templates for repeatable workload resource deployment

Typical Use Cases

Sensitive workloads in isolated networks
Organizations with high protection requirements run applications in zero-trust networks whose virtual networks and NSGs can’t be modified directly and whose traffic flows through managed endpoints.

Air-gapped environments
Per Microsoft, Azure Enclave is explicitly designed for air-gapped environments as well.

Accelerated build-out of compliant environments
Instead of weeks or months of planning, configuration, and testing, Azure Enclave reduces deployment time to hours or days per Microsoft.

Connecting external private networks
Transit hubs combined with community endpoint rules enable secure site-to-site connectivity via VPN Gateway or ExpressRoute.

Benefits

  • Substantially shorter deployment time for secure, compliant environments
  • Multi-layered governance: policy guardrails, managed network boundary, logging, access controls, and connection management
  • Isolation by default: only explicitly defined traffic is allowed
  • Repeatability through validated deployment templates in the service catalog
  • Integration with existing security services such as Microsoft Sentinel, Azure Monitor, Microsoft Defender for Cloud, and Azure Virtual Desktop
  • Logging and diagnostics enabled by default for all enclaves and workloads within a community

Integration with innFactory

As a Microsoft Solutions Partner, innFactory helps you evaluate Azure Enclave against your requirements: we assess whether the preview status is acceptable for your project, design the structure of communities, enclaves, and workloads, and connect existing security and monitoring services.

For production environments we also show alternative paths to isolation and compliance based on Azure landing zones, Azure Policy, and network segmentation. Contact us for a no-obligation consultation.

Typical Use Cases

Isolated environments for highly sensitive workloads
Air-gapped scenarios with strict isolation requirements
Accelerated build-out of compliant cloud environments
Secure site-to-site connectivity to external private networks through transit hubs

Technical Specifications

0th Hierarchy of communities, enclaves, and workloads
1st Community: isolated, zero-trust, Azure Enclave managed virtual WAN boundary with Azure Firewall, policy guardrails, and RBAC deny assignments
2nd Enclave: isolated, zero-trust, managed virtual network with network security groups, policy guardrails, and deny assignments
3rd Workload: logical group linking workload resource groups to an enclave; resources inherit the enclave's security posture, policies, and permissions
4th Community deployment includes Azure Virtual WAN, Azure Firewall, firewall policy, managed identity, and a Log Analytics workspace
5th Enclave deployment includes a virtual network, NSGs per subnet, managed identities, a storage account for flow logs, a key vault, and optionally Log Analytics and Azure Bastion
6th Connection management through enclave endpoints, community endpoints, transit hubs (VPN Gateway or ExpressRoute), and enclave connections
7th Service catalog with validated deployment templates for repeatable workload resource deployment
8th Integration with Microsoft Sentinel, Azure Monitor, Microsoft Defender for Cloud, and Azure Virtual Desktop
9th Enclave virtual networks and NSGs can't be modified directly; they are managed through enclave endpoints and enclave resources

Frequently Asked Questions

Is Azure Enclave production ready?

No. Microsoft states: 'Azure Enclave is currently in preview and is provided without a service-level agreement. At this time, Azure Enclave shouldn't be used for production workloads.' Certain features might not be supported, might have constrained capabilities, or might not be available in all Azure locations.

How does Azure Enclave differ from confidential computing?

Azure Enclave addresses isolated, compliant cloud environments at the networking and governance level through communities, enclaves, and workloads. It should not be confused with the hardware-based enclaves of confidential computing, which protect data in memory during processing.

How is Azure Enclave structured?

Azure Enclave takes a multi-layered and hierarchical approach. A community serves as a central hub for networking, governance, and monitoring for a collection of isolated networks known as enclaves. Enclaves are isolated, zero-trust software-defined networks (Azure Virtual Network) that host your workloads. Workloads are logical groups that link your workload resource groups to an enclave.

Which resources are deployed automatically?

For a community, depending on your selections, Azure Virtual WAN, Azure Firewall, a firewall policy, a managed identity for policy enforcement, and a Log Analytics workspace are created. For an enclave, resources include a virtual network, network security groups per subnet, managed identities, a storage account for network flow logs and a key vault for their encryption, plus optionally Log Analytics and Azure Bastion.

How is outbound connectivity controlled?

Enclave endpoints are collections of networking rules that enable simplified and standardized connectivity to an enclave or an individual workload. Community endpoints enable external connectivity to trusted destinations including public websites, well-known services, and external private networks. Transit hubs can be associated with community endpoint rules to allow secure site-to-site connectivity via VPN Gateway or ExpressRoute.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Certificate Manager - Central TLS Certificate Management

Certificate Manager acquires, manages, and deploys TLS certificates for Cloud Load Balancing, Secure Web Proxy, and …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →
Google Cloud

Cloud Domains - Domain Registration in Google Cloud

Cloud Domains lets you register and manage domains directly in Google Cloud, with billing through Cloud Billing and …

Pricing Per top-level domain pricing as …
SLA SLA as published by the provider
Compare →
Google Cloud

Data Transfer Essentials - Data Transfer Between Cloud Providers

Data Transfer Essentials provides cost-optimized data transfer between the services of an application that resides …

Pricing Currently offered at no charge when used …
SLA SLA as published by the provider
Compare →
Google Cloud

Secure Access Connect - Attach SSE Services to NCC Gateway

Secure Access Connect lets you connect security service edge products to NCC Gateway for security processing and secure …

Pricing Billed according to NCC Gateway pricing …
SLA SLA as published by the provider
Compare →
Google Cloud

Service Extensions - Custom Code in the Network Data Path

Service Extensions inserts custom code into the data path of Cloud Load Balancing, Media CDN, and Secure Web Proxy, as …

Pricing Billed per invocation: plugins on Cloud …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Telecom Network Automation - Cloud-Native Automation for Telecom Networks

Telecom Network Automation is Google's managed cloud implementation of the open source Nephio project for intent-driven …

Pricing Pay-as-you-go per automated vCPU per …
SLA SLA per provider / see official documentation
Compare →

53 comparable products found across other clouds.

Ready to start with Azure Enclave - Isolated, Compliant Environments?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation