Sovereignty Guidance in the Cloud Adoption Framework

Written by 12:55 pm Microsoft Azure

Digital Sovereignty Guidance Is Now Part of the Cloud Adoption Framework

Digital sovereignty has become one of the most energizing conversations in our industry. In customer meetings across EMEA, banks, public sector, healthcare, manufacturing, leaders arrive with a clear ambition: “We want to innovate at full speed, and we want to stay in control. Show us how.”

That’s a great question to be asked. And now there’s a great answer: Digital sovereignty adoption guidance is live in the Microsoft Cloud Adoption Framework (CAF), a clear, structured path from requirements all the way to running workloads. I had the privilege of helping build it, and I couldn’t be happier to see it out in the open.

Two ideas that make this so much easier

Sovereignty is a focused subset of compliance. It zooms in on control, jurisdiction, data residency, administrative access, and operational governance. That focus is liberating, it means the scope is defined, and defined scope is solvable.

Sovereignty is a risk decision you get to make deliberately. You choose which risks to mitigate, which to accept, and how much control is worth its cost. Best of all, sovereignty and security work together: strong security is the foundation that makes sovereign controls meaningful.

The Microsoft Sovereign Cloud Continuum

For years, the assumption was that you had to choose between control and innovation. The sovereign cloud continuum ends that tradeoff: sovereign controls across a range of deployment options, so every workload gets the level of control it needs, all on one common Microsoft platform.

ModelWhat it isGreat when
Sovereign Public CloudSovereign controls on the Azure public cloud you already knowYou want data residency, confidentiality, and operational oversight plus the full pace of Azure innovation
Sovereign Private CloudRuns on Azure Local in facilities you controlWorkloads stay on-premises, connected or fully disconnected. Microsoft 365, Foundry, and GitHub can run locally
National Partner CloudsOperated by a local partner under national governance, in geographies such as Germany and FrancePolicy calls for operational independence from Microsoft

Three things make this genuinely powerful:

  • It’s consistent. Management, services, APIs, governance, and tooling stay the same across models, so your teams’ skills, processes, and investments carry across all of them.
  • It’s transparent. Each step brings more control along with more responsibility, and the guidance spells the tradeoffs out clearly, so you can choose with confidence. Most organizations happily run several models side by side.
  • It’s flexible. As regulations and business conditions evolve, workloads can move along the continuum. Today’s decision doesn’t lock in tomorrow’s architecture.

That’s the real win: one platform, one operating model, and the freedom to dial control up or down per workload.

Three phases, and each one builds on the last

An Azure landing zone gets you started, and the path is refreshingly linear.

1. Planning and organizational readiness. Turn your sovereignty drivers into a requirements catalog with clear owners, then group them into a handful of reusable sovereignty classifications — most organizations thrive with three to five. Keep the thread visible: driver → requirement → risk → control → evidence. The recommended starting point is Sovereign Public Cloud, moving further along the continuum where requirements call for it.

2. Architecture and governance. This is where it gets elegant: a management group per classification, enforcing policies assigned at that level, and application landing zones inheriting the right guardrails automatically. For Azure Local you don’t even add new management groups, the landing zone already includes one. The architecture portability section: design with common identity, governance, and platforms like containers and Kubernetes, and moving along the continuum later stays straightforward.

3. Operational standards. It’s what keeps sovereignty true over time, drift detection, evidence management, operator access, operational data residency, disaster recovery, and a clean onboarding gate. One line worth framing: a sovereignty control you can demonstrate is a sovereignty control you can defend. Get evidence right and audits become routine.

Where to start

Each article ships with a decision tree and downloadable architecture diagrams, including PowerPoint files you can use directly in customer conversations. Don’t skip those.

Thank you to the team

Huge thanks to Stephen Sumner for leading this, and to everyone who shaped it: Mitch Leppo, Fabian Wohlschläger, Mario Szpuszta-Strobl, Janice Wu, Jaimie Fife, Abdelmajid Aneddame, Florian Slezak, Amelia Agrawal, Barbara Beyda, Edouard de Cremiers, John Downs, and Robert Goodrich. A genuine pleasure to work with this group, and the result is now public and free for everyone.

Tags: , , , , , , , , Last modified: September 10, 2026
Close Search Window
Close