Skip to main content
Microsoft Solutions Partner — Sovereignty · 11,000+ engagements

Microsoft Cloud for Sovereignty Enterprise Guide (2026)

Sovereign Landing Zone, Sovereign Cloud Configurator, Microsoft 365 Local, and the EU Data Boundary — the canonical national-cloud architecture for governments and regulated enterprises, activated end-to-end by a senior-architect-led 1997-founded Microsoft Solutions Partner.

How does Microsoft Cloud for Sovereignty meet data residency + national sovereignty requirements? Microsoft Cloud for Sovereignty is the global national-cloud framework that combines a Sovereign Landing Zone reference architecture, the Sovereign Cloud Configurator policy tool, customer-managed keys backed by Azure Key Vault Managed HSM, confidential compute, and Microsoft 365 Local for classified workloads. For European customers it pairs with the EU Data Boundary (completed February 2024), which keeps customer data, system-generated logs, and technical support data inside EU/EFTA regions across Microsoft 365, Dynamics 365, Power Platform, and Azure. Enterprises deploy it through a five-phase Assess, SLZ, Crypto, Data Boundary, Operate program tuned to the chosen regulatory profile — EU GDPR, UK GSC, German BSI C5, French ANSSI SecNumCloud, Saudi NDMO, Japan FISC, or a custom multinational blend.

Microsoft Cloud for Sovereignty is the global national-cloud framework — Sovereign Landing Zone, Sovereign Cloud Configurator, Microsoft 365 Local, customer-managed keys, and the EU Data Boundary. It is the architectural answer for governments and regulated enterprises in the EU, UK, Germany, France, Saudi Arabia, Japan, and other jurisdictions with national-cloud requirements. EPC Group activates the platform end-to-end under a fixed-fee five-phase Sovereignty Accelerator from $300K to $1.5M.

Key Facts

  • Four canonical components — Sovereign Landing Zone, Sovereign Cloud Configurator, Microsoft 365 Local, EU Data Boundary
  • Six national-cloud patterns — EU GDPR, UK GSC, German BSI C5, French ANSSI SecNumCloud, Saudi NDMO, Japan FISC
  • EU Data Boundary completed phased rollout February 2024 across M365, Dynamics 365, Power Platform, and Azure
  • Sovereign Landing Zone ships as open-source Bicep + Terraform inside the AzureSovereign GitHub organization
  • Customer-managed keys + Azure Key Vault Managed HSM (FIPS 140-2 Level 3) is the standard key custody pattern
  • Microsoft 365 Local is the on-premises / partner-hosted M365 variant for classified and air-gapped workloads
  • Microsoft Cloud for Sovereignty complements Azure Government + GCC + GCC High for US federal scope
  • Microsoft Solutions Partner founded in 1997, 70+ Fortune 500 clients, 216+ M&A tenant consolidations

The Microsoft Cloud for Sovereignty components

Microsoft Cloud for Sovereignty is not a single product — it is a framework composed of four canonical building blocks. Together they deliver the residency, key custody, confidential compute, and national-cloud productivity surface required by governments and regulated enterprises operating outside the United States federal sovereign footprint. Understanding what each component does is the first step toward a defensible sovereign architecture.

Sovereign Landing Zone (SLZ) — the reference architecture

What it does: The Sovereign Landing Zone is the Microsoft-published reference architecture for Microsoft Cloud for Sovereignty — a deployable Bicep and Terraform stack that extends the Azure Cloud Adoption Framework Enterprise-Scale Landing Zone with sovereign-by-default controls. SLZ pre-bakes confidential computing, customer-managed keys, data residency policies, sovereign network paths, sovereign logging, and Azure Policy initiatives mapped to national regulatory frameworks. It is the single artifact that turns Microsoft Cloud for Sovereignty from a marketing brand into an auditable deployment.

  • Bicep + Terraform reference implementation aligned to Cloud Adoption Framework Enterprise-Scale
  • Sovereign management group hierarchy with separate confidential, corp, and online landing zones
  • Azure Policy initiative bundles for GDPR, BSI C5, ANSSI SecNumCloud, FedRAMP, and ISO 27018
  • Confidential virtual machines with AMD SEV-SNP and Intel TDX hardware-attested isolation
  • Sovereign logging to a customer-controlled Log Analytics workspace in the sovereign region with optional sovereign HSM-backed log integrity

Licensing: SLZ is published under an open-source MIT-style license inside the Microsoft AzureSovereign repositories. There is no SLZ license SKU — the cost is Azure consumption inside the resulting deployment plus the EPC Group implementation engagement. Confidential VMs, Azure Dedicated HSM, and Azure Key Vault Managed HSM are separately metered Azure services.

Sovereign Cloud Configurator — declarative policy assembly

What it does: The Sovereign Cloud Configurator is the policy-assembly tool that lets architects declaratively pick a regulatory profile (EU GDPR + BSI C5, France SecNumCloud, UK Government Security Classifications, Saudi NDMO, Japan FISC) and emit a policy bundle that drops into the Sovereign Landing Zone. It is how a deployment team avoids hand-authoring 200 individual Azure Policy assignments to satisfy one national framework.

  • Profile-driven generation of Azure Policy initiative assignments, role assignments, and platform configuration
  • Pre-built profiles for 15+ national and regional sovereignty frameworks with continuous Microsoft updates
  • Differential output — emits only the deltas required to bring an existing landing zone into compliance with a new profile
  • Pull-request artifact that ships into GitOps or Azure DevOps pipelines for change review and audit chain-of-custody
  • Compliance Manager binding — each generated policy carries the regulatory citation reviewers ask for during certification

Licensing: Configurator is published as open-source tooling under the AzureSovereign GitHub organization. No license SKU. Use is included in the Microsoft Cloud for Sovereignty deployment pattern and produces artifacts that consume standard Azure Policy and Azure Resource Manager primitives.

Microsoft 365 Local — confidential government and sensitive workloads

What it does: Microsoft 365 Local brings Microsoft 365 productivity (Exchange, SharePoint, Teams, OneDrive) into a customer-operated or partner-operated sovereign environment for jurisdictions where even the EU Data Boundary is insufficient — confidential government tiers, intelligence community workloads, and national-security classified data. It is the M365 equivalent of an air-gapped or disconnected sovereign deployment, with periodic synchronization gates rather than continuous cloud connectivity.

  • On-premises or partner-hosted M365 services with local key custody and local encryption
  • Disconnected or limited-connectivity operation for classified and air-gapped scenarios
  • Local Microsoft Entra ID instance with Conditional Access, Privileged Identity Management, and Identity Protection
  • Periodic update gating with reviewer sign-off before content, code, or telemetry leaves the sovereign perimeter
  • Compatible with Microsoft Cloud for Sovereignty Azure Local infrastructure for unified compute and data residency

Licensing: Microsoft 365 Local is offered under a sovereign-cloud licensing schedule distinct from commercial M365, GCC, and GCC High. Pricing is negotiated via the Microsoft Cloud for Sovereignty enterprise agreement and includes hardware, software, and ongoing security update entitlement. Most deployments are partner-operated under a managed-sovereignty service contract.

EU Data Boundary (EUDB) — data residency for European customers

What it does: The EU Data Boundary commits Microsoft to storing and processing customer data — including diagnostic data and support data — for Microsoft 365, Dynamics 365, Power Platform, and Azure inside the European Union and European Free Trade Association regions. EUDB completed its phased rollout in February 2024 (customer data, system-generated logs, and service-generated personal data, plus technical support data) and is the platform-level answer for Schrems II and post-Schrems II adequacy decisions affecting EU-to-US transfers.

  • Customer data at rest in EU/EFTA regions for M365, Dynamics 365, Power Platform, and Azure
  • System-generated personal data and pseudonymized logs stored in EU/EFTA
  • Technical support data processing inside the EUDB perimeter, with controlled escalation paths to global engineering
  • Encryption-in-transit between EUDB and non-EUDB endpoints with documented exception scenarios
  • EUDB is platform-level — customers retain responsibility for cross-border data flows their own applications, integrations, and connectors create

Licensing: EUDB is included with all Microsoft 365, Dynamics 365, Power Platform, and Azure tenants billed to EU/EFTA addresses or explicitly opted-in via tenant configuration. There is no separate EUDB SKU. The customer cost is the operational discipline required to keep their own integrations, third-party connectors, and exported reports inside the EU perimeter — that is the EPC Group consulting scope.

Six national-cloud deployment patterns

Every Microsoft Cloud for Sovereignty engagement composes from a national-cloud regulatory profile applied to the same four canonical components. EPC Group maintains productized patterns for the six jurisdictions where we see the most demand — extensible to any additional national framework the Sovereign Cloud Configurator supports.

Pattern 1 — EU national and federal government (GDPR + EUDB)

European national governments and federal ministries deploy Microsoft Cloud for Sovereignty on top of the EU Data Boundary to satisfy GDPR Article 28 processor obligations, Schrems II adequacy concerns, and national digital-sovereignty mandates. EPC Group ships the Sovereign Landing Zone with the EU + GDPR profile from the Sovereign Cloud Configurator, customer-managed keys backed by Azure Key Vault Managed HSM in an EU region, sovereign Log Analytics, and Microsoft Purview controls tuned to GDPR data-subject-rights workflows. The result is a deployment where customer data, telemetry, and support data all stay inside the EU perimeter with auditor-ready evidence.

Pattern 2 — UK government (OFFICIAL / OFFICIAL-SENSITIVE)

UK central government departments, devolved administrations, and arms-length bodies deploy on Microsoft Cloud for Sovereignty under the UK Government Security Classifications (GSC) policy. Patterns cover OFFICIAL workloads in commercial Azure UK South / UK West, OFFICIAL-SENSITIVE workloads in the UK sovereign region with customer-managed keys, and Cabinet Office Service Standard alignment. EPC Group integrates the Sovereign Landing Zone with the UK GSC profile, Microsoft Entra Conditional Access policies aligned to the NCSC Cyber Assessment Framework, and Microsoft Purview labeling tuned to GSC handling markings.

Pattern 3 — Germany (BSI Cloud Computing Compliance Criteria Catalogue / C5)

German federal agencies, Länder governments, and regulated enterprises deploy against the BSI C5 catalogue — Cloud Computing Compliance Criteria — which is the de-facto German cloud compliance standard. EPC Group ships the Sovereign Landing Zone with the C5 profile, German-region resource pinning (Germany West Central and Germany North), BSI-aligned encryption key custody, and BSI-aligned logging retention. C5 Type 2 attestation evidence is produced inside Microsoft Compliance Manager and extended with EPC Group operating-control documentation for the customer-owned portion of the shared-responsibility model.

Pattern 4 — France (ANSSI SecNumCloud + Bleu / S3NS partnerships)

French government and OIV (operators of vital importance) deployments target the ANSSI SecNumCloud qualification, the highest French national cloud security standard. EPC Group ships the Sovereign Landing Zone with the SecNumCloud profile, integration patterns for Bleu (the Microsoft + Capgemini + Orange sovereign offering) and S3NS (the Google + Thales joint venture, included only where the customer multi-clouds), and customer-managed keys backed by ANSSI-certified HSMs. SecNumCloud requires French-national-only operations personnel — the EPC Group scope here is architecture and enablement; the day-2 operations contract is signed with the SecNumCloud-qualified operator.

Pattern 5 — Saudi Arabia (NDMO + PDPL + Vision 2030)

Saudi Arabian government, financial services, and oil-and-gas sector deployments operate under the National Data Management Office (NDMO) data classification framework and the Personal Data Protection Law (PDPL). EPC Group ships the Sovereign Landing Zone with the Saudi profile, Azure Saudi Arabia region pinning, customer-managed keys, and NDMO-aligned data classification tied to Microsoft Purview sensitivity labels. The pattern aligns with Vision 2030 digital-sovereignty objectives and the SAMA cybersecurity framework for financial-services workloads.

Pattern 6 — Japan (FISC + APPI + government workloads)

Japanese financial services deployments operate against the FISC Security Reference Manual (FISC安全対策基準) and the Act on the Protection of Personal Information (APPI). Government workloads add JIPDEC certification and the Government Information Systems Security Assessment Program (ISMAP). EPC Group ships the Sovereign Landing Zone with the Japan profile, Azure Japan East / Japan West region pinning, customer-managed keys backed by Azure Dedicated HSM in Japan, and FISC-aligned operating controls. ISMAP-listed services map directly to the Microsoft Cloud for Sovereignty Azure service inventory.

EU Data Boundary — what it covers, what is yours

The EU Data Boundary is platform-level. The customer-side discipline is yours.

EUDB completed its phased rollout in February 2024 across Microsoft 365, Dynamics 365, Power Platform, and Azure. Microsoft now stores and processes customer data, system-generated logs, service-generated personal data, and technical support data inside European Union and European Free Trade Association regions. That commitment is real, contractual, and audited — and it is also only half the picture. The other half is the operating discipline customers owe their own data when it leaves the EUDB perimeter through integrations, third-party connectors, exports, and downstream pipelines they built.

Microsoft covers the platform

Customer data, system-generated logs, service personal data, and technical support data for M365, Dynamics, Power Platform, and Azure stay in EU/EFTA. EUDB is the platform-level Schrems II answer.

You cover the integrations

A Power Automate flow calling a non-EU API. A Logic App posting to a US webhook. A Power BI report exported to an external email. None of those are inside EUDB scope — they are inside customer scope.

EPC Group closes the gap

Cross-border data-flow inventory, exception register, and Microsoft Purview labels and DLP policies tuned to the EU perimeter. The Microsoft platform plus the EPC Group operating control set equals defensible EUDB compliance.

Sovereign cryptography spine

Customer-managed keys, Managed HSM, and confidential compute

Sovereign architecture is enforced cryptographically, not just contractually. EPC Group ships the customer-managed-key (CMK) spine across Azure Storage, Azure SQL, Cosmos DB, Microsoft Fabric OneLake, and Microsoft 365 Customer Key — with the key encryption key (KEK) custody in Azure Key Vault Managed HSM (FIPS 140-2 Level 3, single-tenant) in the sovereign region. For the narrow set of workloads requiring direct customer HSM custody (legacy PKI, payment HSM applications, certain ANSSI SecNumCloud and Saudi NDMO configurations) Azure Dedicated HSM hosts Thales Luna hardware. Confidential virtual machines using AMD SEV-SNP or Intel TDX provide hardware-attested memory isolation for sensitive compute — the cryptographic layer that makes "Microsoft cannot read your data" demonstrable, not just contractual.

Customer-managed keys

CMK at every storage tier — Storage, SQL, Cosmos DB, Fabric OneLake, M365 Customer Key. Key custody in customer-controlled vault, not Microsoft default.

Managed HSM + Dedicated HSM

Azure Key Vault Managed HSM is the FIPS 140-2 Level 3 default; Dedicated HSM reserved for the workloads that require Thales Luna hardware directly.

Confidential compute

AMD SEV-SNP and Intel TDX confidential VMs deliver hardware-attested memory isolation. Microsoft cannot read tenant memory — and the attestation proves it.

Federation with US federal scope

Microsoft Cloud for Sovereignty + Azure Government + GCC + GCC High

Multinational customers operate across multiple sovereign jurisdictions simultaneously — United States federal scope in Azure Government and Microsoft 365 GCC or GCC High, EU member-state scope under Microsoft Cloud for Sovereignty with the GDPR + EUDB profile, UK government scope under the UK GSC profile, and additional national-cloud scopes per country. EPC Group ships the federated control-plane architecture — Microsoft Entra ID tenant federation, cross-tenant access policies, B2B collaboration in supported modes, and Microsoft Defender XDR cross-sovereign incident response — that lets one global security operations team govern a fleet of jurisdiction-specific landing zones without collapsing the sovereign perimeters. See our federal Microsoft consulting hub for the US federal architecture in depth, and our M365 Government vs Google Workspace Federal analysis for the productivity decision frame.

The EPC Group Sovereignty Accelerator — five phases, fixed fee

The accelerator anchors on The EPC Group Lifecycle — Assess, Sovereign Landing Zone, Sovereign Cryptography, EU Data Boundary + Sovereign Workloads, Operate. Fixed-scope between $300,000 and $1.5 million depending on tenant scale, regulatory profile, Microsoft 365 Local in-scope or out, multi-jurisdiction federation requirements, and managed-service tail. Senior-architect led, no offshore handoff.

Phase 1 — Assess

Sovereignty profile selection and gap assessment in three to five weeks

Phase one selects the customer regulatory profile (EU + GDPR, UK GSC, German BSI C5, French ANSSI SecNumCloud, Saudi NDMO, Japan FISC, or a custom blend) and inventories the existing Microsoft cloud estate against that profile. Output is a costed sovereignty roadmap, a risk-weighted backlog, and a board-ready decision package anchoring on the Assess stage of the EPC Group Lifecycle.

  • Regulatory profile selection workshop with legal, security, privacy, and architecture stakeholders
  • Existing Azure, Microsoft 365, Power Platform, and Dynamics 365 footprint inventory with residency and key-custody posture
  • Gap assessment against the chosen sovereignty profile with citation-level mapping
  • Costed five-phase roadmap with Year-1 and Year-2 sequencing and exit-criteria definitions

Phase 2 — Sovereign Landing Zone deployment

Bicep + Terraform SLZ stand-up with the chosen profile

Phase two deploys the Sovereign Landing Zone via Bicep or Terraform, runs the Sovereign Cloud Configurator with the chosen regulatory profile, stands up the sovereign management group hierarchy, and applies the Azure Policy initiative bundle. The output is a sovereign-ready landing zone in the customer tenant with auditable policy enforcement and a documented exception-handling workflow.

  • SLZ Bicep or Terraform deployment with profile-specific overrides for regional pinning and key custody
  • Sovereign management group hierarchy — confidential, corp, online, sandbox, decommissioned
  • Azure Policy initiative assignments mapped to the regulatory framework with deny and audit modes documented
  • GitOps or Azure DevOps integration for landing-zone change control and pull-request review

Phase 3 — Sovereign cryptography and key custody

Customer-managed keys, HSM custody, and confidential compute

Phase three implements the cryptographic spine — customer-managed keys for Azure Storage, Azure SQL, Cosmos DB, Microsoft Fabric OneLake, and Microsoft 365 Customer Key; Azure Key Vault Managed HSM or Azure Dedicated HSM in the sovereign region; confidential virtual machines for sensitive compute; and double key encryption (DKE) for the highest-sensitivity content where the customer retains a second key entirely outside Microsoft.

  • Customer-managed keys (CMK) across Azure Storage, SQL, Cosmos DB, Fabric OneLake, and M365 Customer Key
  • Azure Key Vault Managed HSM (FIPS 140-2 Level 3) or Azure Dedicated HSM in the sovereign region
  • Confidential VMs (AMD SEV-SNP or Intel TDX) for hardware-attested isolation of regulated workloads
  • Microsoft Purview Double Key Encryption (DKE) for the highest-sensitivity Microsoft 365 content

Phase 4 — EU Data Boundary + sovereign workloads

Operationalize EUDB, sovereign M365, and Microsoft 365 Local where required

Phase four operationalizes the EU Data Boundary for European customers, validates EUDB scope across M365, Dynamics 365, Power Platform, and Azure, and stands up Microsoft 365 Local for the subset of workloads where even EUDB is insufficient (confidential government, intelligence community, classified). The deliverable closes the gap between platform-level residency guarantees and customer-side operational discipline.

  • EUDB scope validation across M365, Dynamics 365, Power Platform, and Azure with documented exception list
  • Microsoft 365 Local stand-up for classified, air-gapped, or disconnected sovereign workloads where applicable
  • Cross-border data flow inventory for customer-owned integrations, third-party connectors, and exported reports
  • Sovereign Microsoft Purview labels, DLP policies, and Insider Risk controls tuned to the sovereignty framework

Phase 5 — Operate

Managed sovereign cloud with senior-architect escalation

Phase five is steady-state operation. EPC Group provides managed sovereign-cloud services — policy drift detection, key-rotation orchestration, sovereign log review, regulatory change management, and quarterly sovereignty steering committee output. Senior-architect escalation is the differentiator; tier-one analysts handle routine cases, but every customer has named senior architects on call for the cases that matter to the regulator.

  • Monthly sovereignty health report covering policy drift, residency exceptions, key rotation status, and EUDB scope
  • Quarterly regulatory change review — new EU AI Act provisions, BSI C5 updates, ANSSI guidance, NDMO bulletins
  • Annual sovereignty re-certification cycle with auditor evidence packaging and Compliance Manager output
  • Senior-architect on-call escalation tied to regulator-incident severity matrix

Compliance frameworks — sovereignty mapped to your regulatory reality

Microsoft Cloud for Sovereignty maps directly to GDPR, the EU AI Act, BSI Cloud Computing Compliance Criteria Catalogue (C5), ANSSI SecNumCloud, the UK Government Security Classifications, Saudi NDMO and PDPL, Japan FISC + JIPDEC + ISMAP, and the US federal frameworks (FedRAMP, FISMA, CMMC) for multinational customers. EPC Group extends Microsoft Compliance Manager output into a documented control matrix auditors will accept — assessment evidence, policy references, control owners, and exception management workflows linked to every control claim. See our standards alignment library for the full mapping and our Microsoft Purview enterprise guide for the data-governance layer under the sovereignty framework.

GDPR
EU AI Act
BSI C5
ANSSI SecNumCloud
UK GSC
NDMO + PDPL
FISC + JIPDEC
FedRAMP
ISO 27018
HIPAA
SOC 2
FedRAMP
FINRA
CMMC
GxP

Continue exploring the EPC Group enterprise Microsoft library

Microsoft Cloud for Sovereignty sits at the national-cloud plane inside the broader Microsoft Cloud orchestration story. These hubs and analyses cover adjacent and complementary territory.

Why EPC Group leads enterprise sovereignty deployments

1997
Founded · Microsoft consulting
70+
Fortune 500 clients
216+
M&A tenant consolidations
1.83 million
Users migrated

Microsoft Solutions Partner — Security & Infrastructure

Microsoft Solutions Partner with the Security and Infrastructure designations plus four additional designations covering Modern Work, Data & AI, Digital & App Innovation, and Business Applications. Senior architects average two decades of Microsoft platform delivery experience including sovereign-cloud and federal programs.

Four-time author for Microsoft Press and Sams

Founder Errin O’Connor has nearly three decades of Microsoft consulting leadership and is a four-time author for Microsoft Press and Sams across Power BI and SharePoint — the books regulators, ministries, and Fortune 500 architects keep on the shelf.

Fixed-fee accelerators

Every Sovereignty engagement is fixed-fee with a costed roadmap and a named senior architect on-record from kickoff through go-live. No T&M overruns, no offshore handoff, no junior-analyst-led production cutover into a sovereign perimeter.

Multi-jurisdiction architecture

EPC Group is the Microsoft consulting firm that delivers federated control-plane architectures spanning Azure Government, GCC High, EUDB, sovereign Azure regions, and Microsoft 365 Local — under one program, one accelerator, one senior-architect escalation chain.

Frequently asked questions — Microsoft Cloud for Sovereignty

What is Microsoft Cloud for Sovereignty and how is it different from Azure Government or GCC High?

Microsoft Cloud for Sovereignty is the global, multi-jurisdiction sovereignty platform that gives governments and regulated enterprises outside the United States the same architectural primitives that Azure Government and Microsoft 365 GCC / GCC High give to US federal customers. The differentiator is jurisdictional scope. Azure Government and GCC High operate inside the United States with FedRAMP High and DoD Impact Level controls. Microsoft Cloud for Sovereignty is the framework that delivers equivalent national-cloud architectures for European Union member states, the United Kingdom, Germany, France, Saudi Arabia, Japan, and other jurisdictions with national-cloud requirements. The core building blocks — Sovereign Landing Zone, Sovereign Cloud Configurator, customer-managed keys, confidential compute — are common across all sovereign deployments. The regulatory profile and operating jurisdiction differ.

What does the EU Data Boundary (EUDB) actually cover, and what is still customer responsibility?

The EU Data Boundary commits Microsoft to storing and processing customer data, system-generated logs, service-generated personal data, and technical support data for Microsoft 365, Dynamics 365, Power Platform, and Azure inside the European Union and European Free Trade Association regions. EUDB completed its phased rollout in February 2024. What EUDB does not cover is the customer-side discipline required to keep their own integrations, third-party SaaS connectors, exported reports, and downstream analytics pipelines inside the EU perimeter. A Power BI report exported to a personal email account in the United States is outside EUDB scope. A Power Automate flow that calls a non-EU REST API leaks data outside EUDB scope. EPC Group ships the inventory, exception register, and operating-control workflow that closes that gap.

How does Microsoft 365 Local differ from EUDB and from GCC High?

Microsoft 365 Local is the on-premises or partner-hosted variant of Microsoft 365 designed for confidential government, intelligence community, and classified workloads where even a sovereign-region cloud deployment with customer-managed keys is insufficient. It supports disconnected and air-gapped operation with periodic update gating. EUDB is a platform-level residency commitment inside the public Microsoft 365 service in EU/EFTA regions; M365 Local moves the service itself into the customer-controlled or partner-controlled sovereign perimeter. GCC High is the United States Department of Defense and federal Impact Level 5 variant operated in dedicated US sovereign Azure regions. The three are complementary — most national-government customers run EUDB for unclassified workloads, sovereign Azure regions with customer-managed keys for sensitive workloads, and M365 Local for confidential or classified workloads.

What is the Sovereign Landing Zone and why deploy it instead of the standard Azure Landing Zone?

The Sovereign Landing Zone is the Microsoft-published reference implementation that extends the Cloud Adoption Framework Enterprise-Scale Landing Zone with sovereignty-by-default controls — confidential management group, sovereign network topology, customer-managed keys at every storage tier, sovereign logging to a customer-controlled Log Analytics workspace, and Azure Policy initiative bundles aligned to national regulatory frameworks. The standard Azure Landing Zone is excellent for commercial workloads but does not pre-bake sovereignty controls. Deploying SLZ instead of the standard pattern is the difference between starting compliant and retrofitting compliance — the latter is the most expensive Azure migration scenario in the field. SLZ ships as Bicep and Terraform inside the AzureSovereign GitHub organization and is the foundation EPC Group uses on every sovereignty engagement.

How do customer-managed keys, Managed HSM, and Dedicated HSM fit together in a sovereign deployment?

Customer-managed keys (CMK) is the encryption-at-rest pattern where the key encryption key (KEK) lives inside a customer-controlled key vault rather than the Microsoft-managed default. Azure Key Vault Managed HSM is the FIPS 140-2 Level 3 single-tenant HSM-backed vault Microsoft recommends for sovereign deployments — fully managed, customer-controlled, no Microsoft access to the key material. Azure Dedicated HSM is the bring-your-own-hardware option for customers required to operate Thales Luna HSMs directly. Most sovereign deployments use Managed HSM as the primary key custody and reserve Dedicated HSM for the narrow set of workloads that require it (legacy PKI, payment-card HSM applications, certain Saudi NDMO and ANSSI configurations). EPC Group ships the key-management runbook that defines key rotation cadence, key-recovery procedure, and key-attestation review.

How does Microsoft Cloud for Sovereignty interact with Azure Government, GCC, and GCC High for federal scenarios?

United States federal customers continue to use Azure Government for cloud workloads and Microsoft 365 GCC / GCC High for productivity workloads — those are the FedRAMP High, FedRAMP Moderate, and DoD Impact Level 4/5/6 footprints. Microsoft Cloud for Sovereignty is the parallel framework for non-US national clouds. Where they intersect is a multinational customer with US federal scope plus EU member-state scope plus UK government scope plus Saudi or Japanese scope. The architectural pattern in that case is a federated control plane (Microsoft Entra ID with tenant federation, cross-tenant access policies, and B2B collaboration in supported modes) over jurisdiction-specific landing zones — Azure Government for US federal, sovereign Azure regions for each national-cloud jurisdiction, and managed-sovereignty operating contracts for each. See our /government-federal-microsoft-consulting-fedramp-cmmc-2026 hub for the US federal architecture in depth.

How does the EU AI Act interact with Microsoft Cloud for Sovereignty?

The EU AI Act, in force from August 2024 with staged applicability from February 2025 through August 2027, classifies AI systems into prohibited, high-risk, limited-risk, and minimal-risk tiers and imposes obligations on providers and deployers. For customers deploying Microsoft 365 Copilot, Copilot Studio agents, Azure OpenAI, and Microsoft Fabric AI features in the European Union, the sovereignty framework matters at two layers — data residency for training, fine-tuning, and grounding content (covered by EUDB and customer-managed keys) and AI system governance documentation (covered by Microsoft Purview AI Hub, Microsoft Compliance Manager, and the customer-side risk-management framework). EPC Group ships the EU AI Act gap assessment as part of Phase 1 Assess and extends the Sovereign Landing Zone with AI-system inventory, risk classification, and continuous-monitoring workflows aligned to the Act.

What is the total cost of ownership for a five-phase Sovereignty Accelerator?

EPC Group Sovereignty Accelerator engagements run fixed-fee between $300,000 and $1.5 million depending on tenant scale, regulatory profile complexity, M365 Local in-scope or out-of-scope, multi-jurisdiction federation requirements, and managed-service tail. Azure consumption for the Sovereign Landing Zone, customer-managed keys, Managed HSM, confidential VMs, and sovereign logging is separately metered and typically adds 8 to 15 percent above an equivalent non-sovereign Azure footprint for the regulated workloads. Microsoft 365 Local pricing is negotiated through the Microsoft Cloud for Sovereignty enterprise agreement and depends heavily on the operating jurisdiction. Total cost of ownership in year one for a typical mid-size sovereign deployment is in the $1.5 million to $4 million range; year-two steady-state operations is the managed-services contract plus consumption.

Stand up Microsoft Cloud for Sovereignty — by a partner who has done it

Book a sovereignty briefing with an EPC Group senior architect. Two-hour working session — regulatory profile selection, existing footprint review, Sovereign Landing Zone scoping, customer-managed key custody design, EU Data Boundary gap assessment, accelerator costing. Zero obligation, board-ready output.

AI assistant — not human