The Sovereign Landing Zone (SLZ) is the variant of the Azure landing zone tailored to sovereign requirements.
What is the Sovereign Landing Zone?
Microsoft describes the Sovereign Landing Zone as a variant of the Azure landing zone platform landing zone architecture, tailored to help customers with sovereign requirements meet their specific needs. It adopts the design principles and design areas of the Azure landing zone and incorporates additional controls and principles for the requirements of Sovereign Public Cloud.
The difference from the regular Azure landing zone is precisely scoped and essentially affects two design areas. Resource organization adds the Public, Confidential Corp, and Confidential Online management groups beneath the Landing Zones management group. Security, management, and governance apply or require additional Azure Policies depending on the organization’s sovereignty requirements.
Per Microsoft, Azure billing and Active Directory tenant, identity and access management, network topology and connectivity, and platform automation and DevOps stay unchanged. Organizations that already run an Azure landing zone therefore do not have to start over.
Core Features
- Additional management groups:
Public,Confidential Corp, andConfidential OnlinebeneathLanding Zonesto separate workloads by confidentiality level - Policy as code: additional Azure Policies for residency, confidential computing, and location controls
- Bicep and Terraform implementations: the reference architecture is delivered as code
- Two network topologies: conceptual architectures for hub and spoke and for Virtual WAN
- Compatibility: the same design principles and design areas as the Azure landing zone
Typical Use Cases
Platform baseline for sovereign workloads
Organizations that need a compliant starting point before workloads are migrated or newly built.
Separation by confidentiality level
The additional management groups make it possible to cleanly separate workloads with different confidentiality requirements and assign different policies.
Compliance rollout at scale
Instead of implementing requirements per subscription by hand, they are defined centrally as code and inherited.
Preparing for posture evaluation
A consistently deployed SLZ is the basis for a meaningful assessment in the Sovereign Control Panel.
Benefits
- Building on an established, documented reference architecture instead of a custom design
- Clearly scoped differences from the Azure landing zone, keeping migration effort manageable
- Sovereignty requirements enforced as code rather than through operating procedures
- A choice between hub and spoke and Virtual WAN
- A choice between Bicep and Terraform depending on your existing tooling
Integration with innFactory
Building Azure landing zones is core business for innFactory. As an indirect Microsoft CSP partner, we support you from target architecture through management group structure to policy assignment and automation with Bicep or Terraform.
We describe our approach and the typical pitfalls in detail in Azure Landing Zones as the Foundation of a Scalable Cloud Platform. For organizations bound by professional secrecy, our article on section 203 of the German Criminal Code in the public cloud adds the regulatory perspective.
Contact us for a no-obligation consultation on the Sovereign Landing Zone.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
How does the Sovereign Landing Zone differ from a regular Azure landing zone?
The SLZ is based on the same Azure landing zone architecture and adopts its design principles and design areas. Differences appear in two areas: resource organization adds the Public, Confidential Corp, and Confidential Online management groups beneath the Landing Zones management group, and security, management, and governance apply or require additional Azure Policies depending on the organization's sovereignty requirements.
Which areas stay unchanged compared to the Azure landing zone?
Per Microsoft, Azure billing and Active Directory tenant, identity and access management, network topology and connectivity, and platform automation and DevOps are unchanged.
How is the Sovereign Landing Zone delivered?
Microsoft states the availability of the Sovereign Landing Zone with Bicep and Terraform implementations. It is an opinionated variant of the Azure landing zone that applies policy as code for sovereignty needs, for example residency, confidential computing, and location controls.
Which network topologies are covered?
The documentation shows the conceptual architecture for both a hub and spoke topology and a Virtual WAN topology, plus views of the management group hierarchy alone and the hierarchy with the associated controls and principles applied.
Does the Sovereign Landing Zone cost extra?
Microsoft does not publish a dedicated pricing page for the Sovereign Landing Zone. It is a reference architecture with Bicep and Terraform implementations; billing applies to the Azure resources you deploy with it.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
