Skip to main content
Cloud / Azure / Products / Sovereign Landing Zone - Azure Landing Zone for Sovereign Requirements

Sovereign Landing Zone - Azure Landing Zone for Sovereign Requirements

Sovereign Landing Zone (SLZ): a variant of the Azure landing zone with additional management groups and policy as code for sovereign requirements.

management-and-governance
Pricing Model No separate billing; a reference architecture with Bicep and Terraform implementations, with billing for the Azure resources deployed
Availability Available as a reference architecture and implementation for Sovereign Public Cloud
Data Sovereignty Enforces region and location, encryption, and configuration requirements as policy as code
Reliability No dedicated SLA; the SLAs of the deployed Azure services apply SLA

The Sovereign Landing Zone (SLZ) is the variant of the Azure landing zone tailored to sovereign requirements.

What is the Sovereign Landing Zone?

Microsoft describes the Sovereign Landing Zone as a variant of the Azure landing zone platform landing zone architecture, tailored to help customers with sovereign requirements meet their specific needs. It adopts the design principles and design areas of the Azure landing zone and incorporates additional controls and principles for the requirements of Sovereign Public Cloud.

The difference from the regular Azure landing zone is precisely scoped and essentially affects two design areas. Resource organization adds the Public, Confidential Corp, and Confidential Online management groups beneath the Landing Zones management group. Security, management, and governance apply or require additional Azure Policies depending on the organization’s sovereignty requirements.

Per Microsoft, Azure billing and Active Directory tenant, identity and access management, network topology and connectivity, and platform automation and DevOps stay unchanged. Organizations that already run an Azure landing zone therefore do not have to start over.

Core Features

  • Additional management groups: Public, Confidential Corp, and Confidential Online beneath Landing Zones to separate workloads by confidentiality level
  • Policy as code: additional Azure Policies for residency, confidential computing, and location controls
  • Bicep and Terraform implementations: the reference architecture is delivered as code
  • Two network topologies: conceptual architectures for hub and spoke and for Virtual WAN
  • Compatibility: the same design principles and design areas as the Azure landing zone

Typical Use Cases

Platform baseline for sovereign workloads
Organizations that need a compliant starting point before workloads are migrated or newly built.

Separation by confidentiality level
The additional management groups make it possible to cleanly separate workloads with different confidentiality requirements and assign different policies.

Compliance rollout at scale
Instead of implementing requirements per subscription by hand, they are defined centrally as code and inherited.

Preparing for posture evaluation
A consistently deployed SLZ is the basis for a meaningful assessment in the Sovereign Control Panel.

Benefits

  • Building on an established, documented reference architecture instead of a custom design
  • Clearly scoped differences from the Azure landing zone, keeping migration effort manageable
  • Sovereignty requirements enforced as code rather than through operating procedures
  • A choice between hub and spoke and Virtual WAN
  • A choice between Bicep and Terraform depending on your existing tooling

Integration with innFactory

Building Azure landing zones is core business for innFactory. As an indirect Microsoft CSP partner, we support you from target architecture through management group structure to policy assignment and automation with Bicep or Terraform.

We describe our approach and the typical pitfalls in detail in Azure Landing Zones as the Foundation of a Scalable Cloud Platform. For organizations bound by professional secrecy, our article on section 203 of the German Criminal Code in the public cloud adds the regulatory perspective.

Contact us for a no-obligation consultation on the Sovereign Landing Zone.

Typical Use Cases

Building a compliant platform baseline for sovereign workloads
Separating public and confidential workloads through management groups
Enforcing location and encryption requirements via Azure Policy
Rolling out compliance requirements at scale through infrastructure as code
Preparing environments for posture evaluation in the Sovereign Control Panel

Technical Specifications

0th A variant of the Azure landing zone platform architecture using the same design principles and design areas
1st Adds the Public, Confidential Corp, and Confidential Online management groups beneath the Landing Zones management group
2nd Network topologies: hub and spoke, and Virtual WAN
3rd Additional Azure Policies either applied or required depending on organizational sovereignty requirements
4th No changes versus the Azure landing zone for billing and tenant, identity and access management, network topology and connectivity, and platform automation and DevOps
5th Available as Bicep and Terraform implementations

Frequently Asked Questions

How does the Sovereign Landing Zone differ from a regular Azure landing zone?

The SLZ is based on the same Azure landing zone architecture and adopts its design principles and design areas. Differences appear in two areas: resource organization adds the Public, Confidential Corp, and Confidential Online management groups beneath the Landing Zones management group, and security, management, and governance apply or require additional Azure Policies depending on the organization's sovereignty requirements.

Which areas stay unchanged compared to the Azure landing zone?

Per Microsoft, Azure billing and Active Directory tenant, identity and access management, network topology and connectivity, and platform automation and DevOps are unchanged.

How is the Sovereign Landing Zone delivered?

Microsoft states the availability of the Sovereign Landing Zone with Bicep and Terraform implementations. It is an opinionated variant of the Azure landing zone that applies policy as code for sovereignty needs, for example residency, confidential computing, and location controls.

Which network topologies are covered?

The documentation shows the conceptual architecture for both a hub and spoke topology and a Virtual WAN topology, plus views of the management group hierarchy alone and the hierarchy with the associated controls and principles applied.

Does the Sovereign Landing Zone cost extra?

Microsoft does not publish a dedicated pricing page for the Sovereign Landing Zone. It is a reference architecture with Bicep and Terraform implementations; billing applies to the Azure resources you deploy with it.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with Sovereign Landing Zone - Azure Landing Zone for Sovereign Requirements?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation