What sovereign regions are, who can use them, and how they differ from the public Azure regions.
From Ultra Transcenders AZ-900 by Tony Rough (publishing soon)
Most regions are open to every Azure customer. Sovereign regions are instances of Azure kept separate from the main public (global) cloud, for legal, compliance or data residency reasons. They work like other regions but often have fewer services and features.
| Sovereign cloud | Who it serves | Key facts |
|---|---|---|
| Azure Government | US federal, state and local government agencies and their partners | Physically isolated datacentres and networks in the US only; access to systems processing customer data limited to screened US persons; customers must pass an eligibility check. Regions include US Gov Arizona, US Gov Texas and US Gov Virginia (US Gov Virginia supports availability zones), plus US DoD regions. |
| Microsoft Azure operated by 21Vianet (Azure in China) | Customers who need Azure services in China | A physically separated instance located in China, independently operated and sold by Shanghai Blue Cloud Technology Co., Ltd. (“21Vianet”), a subsidiary of Beijing 21Vianet Broadband Data Center Co., Ltd.; Microsoft doesn’t run the datacentres directly. Regions include China North, China East, China North 2, China East 2, China North 3 and China East 3. A feature parity gap exists, though it is narrowing. |
Azure Government offers IaaS, PaaS and SaaS on the same underlying technologies as global Azure. Developers connect to it differently, but once connected the experience is mostly the same.
Common trap: Thinking any organisation can sign up for Azure Government - customers must be US government entities or their partners and pass eligibility validation, and the service runs only in the US.
This note is one section of Ultra Transcenders AZ-900: Microsoft Azure Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · AZ-900 terms in the glossary · All AZ-900 study notes
Which security and management duties Microsoft owns, which you always keep, and which shift by service type.
What each cloud service type gives you, what you still manage, and typical use cases for each.
How peering connects virtual networks within and across regions, and what traffic and transitivity rules apply.
How each storage redundancy option copies your data and which failures it protects against.
The three Zero Trust principles and how they change the traditional network-perimeter approach to security.
How resource locks prevent accidental deletion or change, how they inherit, and how they differ from RBAC and Policy.
What Azure Advisor recommends across its categories and how it fits alongside Service Health and Azure Monitor.