Skip to main content
Cloud / Azure / Products / Azure Enclave - Isolated, Compliant Environments

Azure Enclave - Isolated, Compliant Environments

Azure Enclave (preview): accelerates building and running secure, isolated, compliant cloud environments through communities, enclaves, and workloads.

networking
Pricing Model Hourly billing per the official pricing page (Azure Virtual Enclaves)
Availability Preview; per Microsoft, certain features might not be available in all Azure locations
Data Sovereignty Designed for commercial and air-gapped environments; region and data handling per official documentation
Reliability No SLA - Azure Enclave is provided without a service-level agreement during preview SLA

What is Azure Enclave?

Azure Enclave accelerates and streamlines the deployment and management of secure, isolated, and compliant cloud environments for the most sensitive workloads. Per Microsoft, it is designed for commercial and air-gapped environments.

Important: Azure Enclave is currently in preview and is provided without a service-level agreement. Microsoft explicitly states that at this time Azure Enclave shouldn’t be used for production workloads. Certain features might not be supported, might have constrained capabilities, or might not be available in all Azure locations.

Azure Enclave takes a multi-layered and hierarchical approach to virtual boundary protection. A community serves as a central hub for networking, governance, and monitoring for a collection of isolated networks known as enclaves. Azure Enclave manages hub and firewall routing along with virtual network flow logging for configured enclave networking paths. Enclaves are isolated, zero-trust software-defined networks (Azure Virtual Network) that host your Azure service workloads. Enclaves and your workloads are governed through policy configuration management with Azure Policy.

Azure Enclave should not be confused with the hardware-based enclaves of confidential computing: Azure Enclave operates at the level of network isolation and governance.

Core Features

  • Communities as a managed virtual WAN boundary with Azure Firewall, policy guardrails, and RBAC deny assignments
  • Enclaves as isolated, managed virtual networks with network security groups and deny assignments
  • Workloads as logical groups whose resources inherit the enclave’s security posture, policies, and permissions
  • Connection management through enclave endpoints, community endpoints, transit hubs, and enclave connections
  • Azure Policy guardrails controlling which resource types and configurations are allowed
  • Logging and monitoring into a community or enclave Log Analytics workspace, depending on configuration
  • Access controls using Azure roles and deny assignments to prevent unauthorized changes to managed resources
  • Service catalog with validated deployment templates for repeatable workload resource deployment

Typical Use Cases

Sensitive workloads in isolated networks
Organizations with high protection requirements run applications in zero-trust networks whose virtual networks and NSGs can’t be modified directly and whose traffic flows through managed endpoints.

Air-gapped environments
Per Microsoft, Azure Enclave is explicitly designed for air-gapped environments as well.

Accelerated build-out of compliant environments
Instead of weeks or months of planning, configuration, and testing, Azure Enclave reduces deployment time to hours or days per Microsoft.

Connecting external private networks
Transit hubs combined with community endpoint rules enable secure site-to-site connectivity via VPN Gateway or ExpressRoute.

Benefits

  • Substantially shorter deployment time for secure, compliant environments
  • Multi-layered governance: policy guardrails, managed network boundary, logging, access controls, and connection management
  • Isolation by default: only explicitly defined traffic is allowed
  • Repeatability through validated deployment templates in the service catalog
  • Integration with existing security services such as Microsoft Sentinel, Azure Monitor, Microsoft Defender for Cloud, and Azure Virtual Desktop
  • Logging and diagnostics enabled by default for all enclaves and workloads within a community

Integration with innFactory

As a Microsoft Solutions Partner, innFactory helps you evaluate Azure Enclave against your requirements: we assess whether the preview status is acceptable for your project, design the structure of communities, enclaves, and workloads, and connect existing security and monitoring services.

For production environments we also show alternative paths to isolation and compliance based on Azure landing zones, Azure Policy, and network segmentation. Contact us for a no-obligation consultation.

Typical Use Cases

Isolated environments for highly sensitive workloads
Air-gapped scenarios with strict isolation requirements
Accelerated build-out of compliant cloud environments
Secure site-to-site connectivity to external private networks through transit hubs

Technical Specifications

0th Hierarchy of communities, enclaves, and workloads
1st Community: isolated, zero-trust, Azure Enclave managed virtual WAN boundary with Azure Firewall, policy guardrails, and RBAC deny assignments
2nd Enclave: isolated, zero-trust, managed virtual network with network security groups, policy guardrails, and deny assignments
3rd Workload: logical group linking workload resource groups to an enclave; resources inherit the enclave's security posture, policies, and permissions
4th Community deployment includes Azure Virtual WAN, Azure Firewall, firewall policy, managed identity, and a Log Analytics workspace
5th Enclave deployment includes a virtual network, NSGs per subnet, managed identities, a storage account for flow logs, a key vault, and optionally Log Analytics and Azure Bastion
6th Connection management through enclave endpoints, community endpoints, transit hubs (VPN Gateway or ExpressRoute), and enclave connections
7th Service catalog with validated deployment templates for repeatable workload resource deployment
8th Integration with Microsoft Sentinel, Azure Monitor, Microsoft Defender for Cloud, and Azure Virtual Desktop
9th Enclave virtual networks and NSGs can't be modified directly; they are managed through enclave endpoints and enclave resources

Frequently Asked Questions

Is Azure Enclave production ready?

No. Microsoft states: 'Azure Enclave is currently in preview and is provided without a service-level agreement. At this time, Azure Enclave shouldn't be used for production workloads.' Certain features might not be supported, might have constrained capabilities, or might not be available in all Azure locations.

How does Azure Enclave differ from confidential computing?

Azure Enclave addresses isolated, compliant cloud environments at the networking and governance level through communities, enclaves, and workloads. It should not be confused with the hardware-based enclaves of confidential computing, which protect data in memory during processing.

How is Azure Enclave structured?

Azure Enclave takes a multi-layered and hierarchical approach. A community serves as a central hub for networking, governance, and monitoring for a collection of isolated networks known as enclaves. Enclaves are isolated, zero-trust software-defined networks (Azure Virtual Network) that host your workloads. Workloads are logical groups that link your workload resource groups to an enclave.

Which resources are deployed automatically?

For a community, depending on your selections, Azure Virtual WAN, Azure Firewall, a firewall policy, a managed identity for policy enforcement, and a Log Analytics workspace are created. For an enclave, resources include a virtual network, network security groups per subnet, managed identities, a storage account for network flow logs and a key vault for their encryption, plus optionally Log Analytics and Azure Bastion.

How is outbound connectivity controlled?

Enclave endpoints are collections of networking rules that enable simplified and standardized connectivity to an enclave or an individual workload. Community endpoints enable external connectivity to trusted destinations including public websites, well-known services, and external private networks. Transit hubs can be associated with community endpoint rules to allow secure site-to-site connectivity via VPN Gateway or ExpressRoute.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

STACKIT

STACKIT Application Load Balancer: Layer 7 Routing

STACKIT Application Load Balancer distributes HTTP/HTTPS traffic via Layer 7 routing by URL path, host, and headers from …

Pricing Pay-per-use (based on usage/throughput)
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT CDN - Content Delivery Network

STACKIT CDN: content delivery with selectable delivery regions, optional origin at STACKIT, WAF, DDoS protection, and …

Pricing Pay-per-use, price per MB of data …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT DNS - Managed DNS Service

STACKIT DNS: authoritative DNS hosting with an anycast network from German data centers, GDPR-compliant.

Pricing Hourly tiered pricing per zone based on …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT DNS Resolver - Recursive DNS

STACKIT DNS Resolver: sovereign, recursive DNS resolution for workloads in the STACKIT Cloud with DNSSEC validation and …

Pricing Free, no ordering process
SLA N/A (Beta)
Compare →
STACKIT

STACKIT Network Load Balancer - Layer 4 Load Balancing

STACKIT Network Load Balancer: Layer 4 load balancing (TCP/UDP) from Germany. Health checks, TLS passthrough, …

Pricing Pay-per-use (usage/throughput)
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Network Security - Firewall & Security Groups

STACKIT Network Security: Security Groups, Unified Firewall, and STACKIT Network Area from Germany. GDPR-compliant.

Pricing Security groups and networking included …
SLA SLA as published by the provider
Compare →

53 comparable products found across other clouds.

Ready to start with Azure Enclave - Isolated, Compliant Environments?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation