What is Azure Enclave?
Azure Enclave accelerates and streamlines the deployment and management of secure, isolated, and compliant cloud environments for the most sensitive workloads. Per Microsoft, it is designed for commercial and air-gapped environments.
Important: Azure Enclave is currently in preview and is provided without a service-level agreement. Microsoft explicitly states that at this time Azure Enclave shouldn’t be used for production workloads. Certain features might not be supported, might have constrained capabilities, or might not be available in all Azure locations.
Azure Enclave takes a multi-layered and hierarchical approach to virtual boundary protection. A community serves as a central hub for networking, governance, and monitoring for a collection of isolated networks known as enclaves. Azure Enclave manages hub and firewall routing along with virtual network flow logging for configured enclave networking paths. Enclaves are isolated, zero-trust software-defined networks (Azure Virtual Network) that host your Azure service workloads. Enclaves and your workloads are governed through policy configuration management with Azure Policy.
Azure Enclave should not be confused with the hardware-based enclaves of confidential computing: Azure Enclave operates at the level of network isolation and governance.
Core Features
- Communities as a managed virtual WAN boundary with Azure Firewall, policy guardrails, and RBAC deny assignments
- Enclaves as isolated, managed virtual networks with network security groups and deny assignments
- Workloads as logical groups whose resources inherit the enclave’s security posture, policies, and permissions
- Connection management through enclave endpoints, community endpoints, transit hubs, and enclave connections
- Azure Policy guardrails controlling which resource types and configurations are allowed
- Logging and monitoring into a community or enclave Log Analytics workspace, depending on configuration
- Access controls using Azure roles and deny assignments to prevent unauthorized changes to managed resources
- Service catalog with validated deployment templates for repeatable workload resource deployment
Typical Use Cases
Sensitive workloads in isolated networks
Organizations with high protection requirements run applications in zero-trust networks whose virtual networks and NSGs can’t be modified directly and whose traffic flows through managed endpoints.
Air-gapped environments
Per Microsoft, Azure Enclave is explicitly designed for air-gapped environments as well.
Accelerated build-out of compliant environments
Instead of weeks or months of planning, configuration, and testing, Azure Enclave reduces deployment time to hours or days per Microsoft.
Connecting external private networks
Transit hubs combined with community endpoint rules enable secure site-to-site connectivity via VPN Gateway or ExpressRoute.
Benefits
- Substantially shorter deployment time for secure, compliant environments
- Multi-layered governance: policy guardrails, managed network boundary, logging, access controls, and connection management
- Isolation by default: only explicitly defined traffic is allowed
- Repeatability through validated deployment templates in the service catalog
- Integration with existing security services such as Microsoft Sentinel, Azure Monitor, Microsoft Defender for Cloud, and Azure Virtual Desktop
- Logging and diagnostics enabled by default for all enclaves and workloads within a community
Integration with innFactory
As a Microsoft Solutions Partner, innFactory helps you evaluate Azure Enclave against your requirements: we assess whether the preview status is acceptable for your project, design the structure of communities, enclaves, and workloads, and connect existing security and monitoring services.
For production environments we also show alternative paths to isolation and compliance based on Azure landing zones, Azure Policy, and network segmentation. Contact us for a no-obligation consultation.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
Is Azure Enclave production ready?
No. Microsoft states: 'Azure Enclave is currently in preview and is provided without a service-level agreement. At this time, Azure Enclave shouldn't be used for production workloads.' Certain features might not be supported, might have constrained capabilities, or might not be available in all Azure locations.
How does Azure Enclave differ from confidential computing?
Azure Enclave addresses isolated, compliant cloud environments at the networking and governance level through communities, enclaves, and workloads. It should not be confused with the hardware-based enclaves of confidential computing, which protect data in memory during processing.
How is Azure Enclave structured?
Azure Enclave takes a multi-layered and hierarchical approach. A community serves as a central hub for networking, governance, and monitoring for a collection of isolated networks known as enclaves. Enclaves are isolated, zero-trust software-defined networks (Azure Virtual Network) that host your workloads. Workloads are logical groups that link your workload resource groups to an enclave.
Which resources are deployed automatically?
For a community, depending on your selections, Azure Virtual WAN, Azure Firewall, a firewall policy, a managed identity for policy enforcement, and a Log Analytics workspace are created. For an enclave, resources include a virtual network, network security groups per subnet, managed identities, a storage account for network flow logs and a key vault for their encryption, plus optionally Log Analytics and Azure Bastion.
How is outbound connectivity controlled?
Enclave endpoints are collections of networking rules that enable simplified and standardized connectivity to an enclave or an individual workload. Community endpoints enable external connectivity to trusted destinations including public websites, well-known services, and external private networks. Transit hubs can be associated with community endpoint rules to allow secure site-to-site connectivity via VPN Gateway or ExpressRoute.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
