The Sovereign Control Panel (SCP) is the central Azure portal experience for discovering, controlling, and remediating your sovereignty posture.
What is the Sovereign Control Panel?
Microsoft describes the Sovereign Control Panel as the integration point for sovereignty in its public cloud. It aggregates sovereignty signals into a centralized console and provides a unified Azure portal experience for viewing, managing, and evaluating sovereignty posture across tenant resources.
Note the rename: Microsoft states in the documentation that Regulated Environment Management (REM) is now Sovereign Control Panel (SCP). If you are still looking for REM, this is where the capability lives.
Microsoft states the motivation plainly: for regulated organizations, proving sovereignty is often harder than implementing it. Teams spend far more effort assembling evidence than enabling controls. That is exactly the gap SCP addresses.
Core Features
- Discover: a read-only, evidence-based view of your posture across residency, confidentiality, operational sovereignty, and continuity
- Control: set and enforce the controls your organization requires, including your own sovereignty rules
- Act: prioritize sovereign risk and remediate resources that drift from the expected state
- Single view of posture: one authoritative sovereignty view across the tenant, management group, subscription, and resource hierarchy instead of fragmented tool-by-tool checks
- Evidence, not policy assertion: combines Azure Policy evaluations with direct resource configuration reads
Typical Use Cases
Evidence for auditors
Organizations that need a defensible answer to “where do I stand?” get an evidence-based view instead of a collection of individual reports.
Governance across large tenants
The hierarchical view across management groups and subscriptions makes it possible to spot deviations where they originate.
Custom sovereignty rules
Organizations with industry-specific requirements can define their own rules and measure adherence to them.
Remediating drift
Resources that drift from the expected state can be prioritized and corrected rather than discovered in the next audit.
Benefits
- One central view instead of tool-by-tool checks
- Coverage even where no matching policy alias exists
- Traceable evidence for audits and regulatory reviews
- Alignment with regulatory frameworks such as the SEAL framework referenced by Microsoft
- A continuous operating model from detection through remediation
Integration with innFactory
As an indirect Microsoft CSP partner, innFactory helps you translate your sovereignty requirements into measurable controls and integrate the posture assessment in the Sovereign Control Panel into your governance processes.
The technical basis for this is usually a cleanly structured landing zone with policy as code; we describe our approach in our article on Azure Landing Zones.
Contact us for a no-obligation consultation on governance and compliance on Microsoft Azure.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What happened to Regulated Environment Management (REM)?
Microsoft states it explicitly in the documentation: "Regulated Environment Management (REM) is now Sovereign Control Panel (SCP)." It is a rename of the same capability.
What does the Sovereign Control Panel actually do?
SCP is the integration point for sovereignty in Microsoft's public cloud. It provides a unified Azure portal experience for viewing, managing, and evaluating sovereignty posture across tenant resources, aggregating sovereignty signals into a centralized console. The operating model follows three steps: Discover, Control, and Act.
How does SCP differ from plain Azure Policy evaluations?
Microsoft highlights that SCP combines Azure Policy evaluations with direct resource configuration reads, so coverage is not limited to where a policy alias happens to exist. Microsoft describes this as "Evidence, not policy assertion."
Is the Sovereign Control Panel generally available?
The official documentation page carries neither a preview nor a GA banner. Its status therefore cannot be established conclusively from the official sources; refer to the official documentation and your contract terms.
Who is the Sovereign Control Panel intended for?
Microsoft names national and federal government and public sector agencies, regulated industries such as financial, healthcare, defense, energy, and critical infrastructure services, and national and sovereign cloud operators. As an example of a regulatory framework, the documentation references the SEAL framework.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
