Azure confidential computing protects data while it is being processed - the state that encryption at rest and in transit does not cover.
What is Azure Confidential Computing?
Confidential computing is an industry term established by the Confidential Computing Consortium (CCC), part of the Linux Foundation. The CCC defines it as protecting data in use by performing computation in a hardware-based, attested Trusted Execution Environment. These secure and isolated environments prevent unauthorized access to or modification of applications and data while they are in use. Microsoft is a founding member of the CCC and provides TEEs in Azure based on that definition.
Azure already encrypts data at rest and in transit. Confidential computing closes the third gap: protecting data in use, including protection for cryptographic keys. The threat model explicitly aims to reduce trust in - or remove the ability of - the cloud provider operator to access code and data while it is being executed. Azure uses a hardware root of trust that is not controlled by the cloud provider.
In practical terms: when Azure confidential computing is enabled and properly configured, Microsoft states that it cannot access unencrypted customer data. This is precisely why Microsoft also lists confidential computing as one of the foundational capabilities of Sovereign Public Cloud.
Core Features
- AMD SEV-SNP confidential VMs: DCasv5 and ECasv5 to rehost existing workloads while protecting data from cloud operators; DCasv6 and ECasv6 are in gated preview
- Intel TDX confidential VMs: DCesv6 and ECesv6 for VM-level confidentiality
- Confidential GPU VMs: NCCadsH100v5 combines GPU performance with linked CPU and GPU TEEs for sensitive AI and machine learning workloads
- Confidential AKS worker nodes: rehost containers with worker-node-level confidentiality on AMD SEV-SNP hardware
- Confidential containers on Azure Container Instances: container-level integrity and attestation through confidential computing enforcement (CCE) policies
- Complementary services: Azure Attestation, Azure confidential ledger, Azure Key Vault Managed HSM, and Always Encrypted with secure enclaves in Azure SQL
Typical Use Cases
Regulated data processing
Organizations that process highly sensitive data and must technically exclude access by the cloud operator.
Confidential AI workloads
NCCadsH100v5 protects models and input data while computation runs on the GPU. Microsoft also names confidential inferencing with the Azure OpenAI Whisper model as a concrete scenario.
Rehosting existing applications
Microsoft describes the confidential VM series as explicitly designed to move existing workloads into a protected environment without redesign.
Container workloads with attestation
Confidential containers on Azure Container Instances address scenarios where container integrity must be verifiable.
Sovereign architectures
Within Sovereign Public Cloud, confidential computing serves as a building block for limiting operational access risk during processing.
Benefits
- Closes the gap between encryption at rest and encryption in transit
- A hardware root of trust that is not controlled by the cloud provider
- Attestation through Azure Attestation as verifiable proof of the environment
- A broad range of options from VMs to AKS nodes to Container Instances
- Compatible with sovereign architecture patterns such as the Sovereign Landing Zone
Integration with innFactory
As an indirect Microsoft CSP partner, innFactory helps you select the right confidential computing building blocks: which VM series suits your workload, when confidential AKS nodes make more sense than confidential containers, and how attestation fits into your operating processes.
For regulated environments we place the result within your overall concept - the legal requirements for organizations bound by professional secrecy are covered in our article on section 203 of the German Criminal Code in the public cloud. Platform-side implementation is anchored in an Azure Landing Zone.
Contact us for a no-obligation consultation on confidential computing on Microsoft Azure.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is confidential computing?
Confidential computing is an industry term established by the Confidential Computing Consortium (CCC), part of the Linux Foundation. The CCC defines it as: "Confidential Computing protects data in use by performing computation in a hardware-based, attested Trusted Execution Environment." Microsoft is a founding member of the CCC and provides TEEs in Azure based on that definition.
Does confidential computing also protect against the cloud operator?
Yes, that is the explicit goal. Microsoft states that Azure confidential computing helps customers prevent unauthorized access to data in use, including from the cloud operator, by processing data in a hardware-based and attested TEE. When Azure confidential computing is enabled and properly configured, Microsoft can't access unencrypted customer data.
Which VM series are available?
For AMD SEV-SNP, Microsoft names the DCasv5 and ECasv5 series; DCasv6 and ECasv6 are currently in gated preview. For Intel TDX, DCesv6 and ECesv6 are available. For confidential AI workloads, the NCCadsH100v5 confidential GPU VM combines GPU performance with linked CPU and GPU TEEs.
Is confidential computing available for containers?
Yes. Microsoft names confidential VM AKS worker nodes on AMD SEV-SNP hardware for worker-node-level confidentiality, and confidential containers on Azure Container Instances, which support container-level integrity and attestation through confidential computing enforcement (CCE) policies.
Which other Azure services build on confidential computing?
Microsoft lists Azure Key Vault Managed HSM, Azure Attestation for remote attestation of TEEs, Azure confidential ledger as a tamper-evident write-once store, Always Encrypted with secure enclaves in Azure SQL, Azure Virtual Desktop, and Azure Databricks, among others.
What does confidential computing cost?
Microsoft does not publish a dedicated pricing page for confidential computing. Billing applies to the resources you use, in particular the respective VM series. Current prices are on the Azure VM series pricing page.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
