Sovereign Public Cloud is Microsoft’s approach to meeting sovereignty requirements inside the existing hyperscale regions rather than building a separate cloud.
What is Sovereign Public Cloud?
Microsoft describes Sovereign Public Cloud as its approach to supporting the digital sovereignty goals of governments and regulated industries while using existing Microsoft hyperscale cloud regions. It combines public cloud innovation with added controls for data residency, operational oversight, and customer-controlled encryption.
At a high level, Sovereign Public Cloud rests on three layers: the hyperscale foundation of Azure and Microsoft 365, sovereignty guardrails through policy initiatives and landing zones, and operational transparency in which access to European services is EU-resident controlled and tamper-evidently logged. Customer-managed keys and confidential computing complete the picture.
For EU and EFTA datacenters, Microsoft explicitly names two additional building blocks: the EU Data Boundary and Data Guardian.
Core Features
- Data Guardian: authorized regional personnel approve and monitor remote access by Microsoft personnel; all access is recorded in a tamper-evident ledger
- External Key Management: generate, store, and manage encryption keys outside Microsoft’s cloud boundary, for example in customer-operated or trusted third-party HSMs
- Confidential Computing: protects data in use by running computations inside hardware-based Trusted Execution Environments
- Sovereign Control Panel (SCP): unified Azure portal experience for viewing, managing, and evaluating sovereignty posture across tenant resources
- Sovereign Landing Zone (SLZ): policy-as-code guardrails as a Bicep and Terraform implementation
- Data residency: the ability to keep data in-region, complemented by Advanced Data Residency in Microsoft 365
Typical Use Cases
Public sector
National, regional, and local agencies that want to use public cloud services while complying with local legal requirements.
Regulated industries
Energy utilities, healthcare providers, and financial services firms that need data residency and operational evidence for regulators.
Audit evidence
Organizations that must demonstrate who accessed which systems and when. Data Guardian provides an immutable audit trail for this.
Key custody
Environments in which encryption keys must demonstrably sit outside the cloud provider’s control.
Benefits
- Sovereignty controls without giving up the scale, innovation pace, and resiliency of the hyperscale cloud
- Operational transparency through regionally controlled access and tamper-evident logging
- Key custody via External Key Management with HSM-based key stores
- Scalable compliance through policy as code instead of manual per-resource configuration
- A central view of sovereignty posture through the Sovereign Control Panel
Integration with innFactory
As an indirect Microsoft CSP partner, innFactory supports you in building sovereign Azure environments: from assessing your compliance requirements and selecting the right sovereignty capabilities to implementing the guardrails as infrastructure as code.
The foundation is usually a cleanly designed landing zone. We describe our approach in Azure Landing Zones as the Foundation of a Scalable Cloud Platform. For organizations bound by professional secrecy, our article on section 203 of the German Criminal Code in the public cloud adds the legal perspective.
Contact us for a no-obligation consultation on Sovereign Public Cloud.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
How does Sovereign Public Cloud differ from the regular Azure public cloud?
Sovereign Public Cloud uses the same Microsoft hyperscale regions but layers sovereignty controls on top. Microsoft names four foundational capabilities: Data Guardian for regional oversight of operational access, External Key Management for customer-controlled keys, Confidential Computing for protecting data in use, and the Sovereign Control Panel for centrally evaluating sovereignty posture.
Does Sovereign Public Cloud cost extra?
Microsoft does not publish a dedicated pricing page for Sovereign Public Cloud. These are sovereignty capabilities on existing Azure regions; billing applies to the services you consume plus any licenses for individual building blocks. For a concrete cost assessment, refer to the official documentation and your contract terms.
Who should consider Sovereign Public Cloud?
According to Microsoft, national, regional, and local governments as well as regulated industries such as energy, healthcare, and financial services operating in Europe, where data residency, operational oversight, and compliance requirements must be met.
How does Sovereign Public Cloud relate to the EU Data Boundary?
Microsoft describes the EU Data Boundary as one of the specific sovereignty features for EU/EFTA datacenters within Sovereign Public Cloud, keeping data in Europe under EU law and control.
How are compliance requirements enforced technically?
Through codified guardrails. Microsoft names policy as code and landing zones that let customers configure, deploy, and monitor compliant environments at scale. The Sovereign Landing Zone is available as a Bicep and Terraform implementation for this purpose.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
