Microsoft released a new sovereign cloud offering aimed at accelerating government customers' digital transformation while prioritizing compliance, security and policy requirements.
With 71% of countries worldwide subject to data protection and privacy laws, and another 9% of countries with legislation in draft stages, government customers have experienced regulatory limitations in shifting their systems and infrastructure to the cloud.
The substantial costs of owning and operating private data centers, for example, pose a major hurdle to modernization, and "innovators within global governments have asked for alternatives to the heavy capital expense and operational costs of a legacy approach," Microsoft Corporate VP of Cloud for Industry Corey Sanders wrote in a blog.
Paired with this summer's policy decision between the European Union (EU) and the U.S. under the General Data Protection Regulation (GDPR) to provide legal support for EU government customers of hyperscale data center providers like Microsoft, the company sees this offering as a clear way to address both those trends.
To that point, Microsoft Cloud for Sovereignty is founded on repeatable best-practice approaches that are ideal for complex regulatory requirements, and the offering's data sovereignty and encryption controls will help governments tailor their cloud environment based on regional or national laws, Sanders said.
Data transparency and choiceMicrosoft's strategy for digital sovereignty in the cloud is based on its strategy for data privacy in the cloud. Since sovereignty is often defined differently based on who you ask, that's the common thread between all of Microsoft's customers, who "need to determine for themselves where their data resides and how it's protected, including who has access to that data," Sanders said. "We believe in transparency so that people and organizations can control their data and have meaningful choices in how it’s used."
While Microsoft claims its public cloud already delivers on the security, privacy and compliance needs of most governments, Microsoft Cloud for Sovereignty adds capabilities designed for countries with specific jurisdictional requirements for sensitive data.
As part of the public preview, Microsoft has made its Sovereign Landing Zone policy initiative available on GitHub, which provides examples of guardrails for workloads in sovereign cloud environments and best practices for securing those environments according to local regulations.
The offering also includes Transparency Logs for eligible customers to gain visibility into Microsoft engineers' key operational activities as they support service and reliability issues. And automated workload templates for Azure Confidential Computing are available as guidelines for creating workloads using sovereign-ready technologies. These features of the offering will accelerate both adoption of cloud infrastructure and education on cloud sovereignty, Sanders said.
Cloud sovereignty in SwedenSwedish IT infrastructure provider Atea has integrated the security capabilities of Microsoft Cloud for Sovereignty to take advantage of the public cloud while adhering to sensitive data management needs.
As a Microsoft customer, Atea is supporting customer use cases like advanced predictive health care analytics with the hyperscaler's sovereign cloud offer. In this way, Atea "is empowering public customers to deliver digital services and assisting government agencies in improving citizens’ digital experiences," Sanders said.
Microsoft Cloud for Sovereignty is currently available in public preview, and the hyperscaler plans to push the offering into GA by December.
Comments