Microsoft Sovereign Cloud is the umbrella brand for Microsoft’s sovereign cloud offerings. It groups the capabilities and deployment models that help governments and regulated industries meet data residency, compliance, and operational sovereignty requirements.
What is Microsoft Sovereign Cloud?
According to the official documentation, Microsoft Sovereign Cloud is an evolution and expansion of the earlier Microsoft Cloud for Sovereignty offering. Microsoft describes it as a suite of capabilities and deployment models designed to help governments and regulated industries meet stringent data residency, compliance, and operational sovereignty requirements without sacrificing the benefits of hyperscale cloud innovation.
Microsoft Sovereign Cloud is available across European datacenter regions for European customers and supports enterprise services such as Microsoft Azure, Microsoft 365, Microsoft Security, and Power Platform. Microsoft also states that the technical capabilities to enforce data sovereignty are available worldwide.
An important distinction: this is not a single purchasable service but a portfolio. You choose the deployment model that fits your requirements and run the regular Microsoft services inside it under additional sovereignty controls.
Core Features
- Sovereign Public Cloud: hosted in Microsoft-operated datacenters within defined geopolitical boundaries such as the EU Data Boundary, with data residency, customer-managed encryption keys, and operational transparency
- Sovereign Private Cloud: runs in customer-controlled or partner-operated datacenters, delivered via Azure Local, Microsoft 365 Local, GitHub Enterprise Local, and Foundry Local on Azure Local
- National Partner Clouds: localized sovereign cloud instances operated together with an approved national or regional partner
- Sovereign Landing Zone (SLZ): preconfigured Azure environment with policy-as-code templates that enforce compliance and security baselines
- Confidential Computing: protects data in use with hardware-based Trusted Execution Environments
- Data Guardian and External Key Management: additional sovereignty controls within Sovereign Public Cloud
Typical Use Cases
Public sector
National, regional, and local government agencies that want to adopt cloud services while remaining bound by legal requirements on data handling and operations.
Regulated industries
Microsoft explicitly names energy, healthcare, and financial services as target groups that need data residency, operational oversight, and compliance evidence.
Defense and critical infrastructure
For scenarios requiring disconnected operation or full control over the infrastructure, Microsoft points to Sovereign Private Cloud.
National sovereignty frameworks
Where national regulation requires a domestically operated provider, National Partner Clouds address that requirement.
Benefits
- One coherent portfolio instead of isolated solutions: public, private, and partner models under a single brand
- Access to the same Azure and Microsoft 365 services as the global cloud, with added sovereignty controls
- Codified guardrails through policy-as-code and the Sovereign Landing Zone instead of manual configuration
- Protection of data at rest, in transit, and in use through confidential computing and customer-managed keys
- Auditability through tamper-evident logs for operational access
Integration with innFactory
As an indirect Microsoft CSP partner, innFactory supports you in selecting and adopting the sovereign deployment model that fits your requirements. Together we assess which of your workloads belong in the Sovereign Public Cloud and where a Sovereign Private Cloud or a National Partner Cloud is the better answer.
For building the platform itself, we draw on our experience with Azure Landing Zones. For organizations bound by professional secrecy obligations, we have summarized the legal and technical requirements in our article on professional secrecy under section 203 of the German Criminal Code in the public cloud.
Contact us for a no-obligation consultation on sovereign cloud architectures on Microsoft Azure.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is the difference between Microsoft Sovereign Cloud and Microsoft Cloud for Sovereignty?
Microsoft describes Microsoft Sovereign Cloud in the official documentation as an evolution of the earlier offering: "Microsoft Sovereign Cloud, formerly Microsoft Cloud for Sovereignty, is an evolution and expansion of the original offering." It is the same product family under a new name and with an expanded scope.
Is Microsoft Sovereign Cloud a single service I can purchase?
No. Microsoft Sovereign Cloud is an umbrella for a set of capabilities and deployment models, not a single billable Azure service. You select a deployment model - Sovereign Public Cloud, Sovereign Private Cloud, or a National Partner Cloud - and consume the relevant Azure and Microsoft 365 services within it. Billing applies to the services you use.
Which deployment models are available?
The documentation names three models: Sovereign Public Cloud in Microsoft-operated datacenters within defined geopolitical boundaries, Sovereign Private Cloud in customer- or partner-operated datacenters built on Azure Local, and National Partner Clouds delivered with an approved national or regional partner.
Does Microsoft Sovereign Cloud apply only to Europe?
Microsoft states that Microsoft Sovereign Cloud is available across European datacenter regions for European customers. At the same time, Microsoft notes that the technical capabilities to enforce data sovereignty are available worldwide. The scope and availability of National Partner Clouds vary by country.
Which components does it include?
Microsoft lists Sovereign Landing Zone (SLZ), Azure Local, Microsoft 365 Local, Confidential Computing, GitHub Enterprise Local, and Foundry Local on Azure Local as core components.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
