Builds on the Azure platform landing zone's design principles and library, adding sovereignty measures such as keeping data in a region, customer-managed keys and confidential computing. It is not meant to replace an Azure landing zone already in place.
Also called SLZ.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Sovereign Landing Zone in context, with comparison tables and the common traps.
Terms in this definition
- Platform landing zone
Typically one per Microsoft Entra tenant, this is the shared core that everything else rests on. It comprises the management group structure, common services for networking, identity, management and security, and the route by which teams receive their own landing zones.
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
- Customer-managed keys
RSA or RSA-HSM key of 2048, 3072 or 4096 bits that you keep in Key Vault or Managed HSM to wrap a storage account's encryption key. You can switch it on later, except for tables and queues, whose CMK support must be chosen at creation.
- Confidential computing
Keeping data safe while it is being used by processing it in an attested, hardware-based trusted execution environment (TEE), which even the cloud provider cannot see into. It adds to encryption of stored data and data on the move.
- Azure landing zone
The architecture Microsoft recommends for running a multi-subscription Azure environment that is governed, secure and able to scale. It consists of a single platform landing zone plus workload landing zones operating inside the guardrails it provides.
Related terms
- Azure landing zones library
Released in numbered versions and found under
platform/alz, this is where the Bicep and Terraform modules get the policy content and archetypes they deploy. Sovereign Landing Zone extends it. - Confidential Corp
For internal-only workloads handling highly confidential data, this Sovereign Landing Zone group, beneath Landing zones, takes the Corp policies and adds confidential computing controls that protect data while in use.
- Confidential Online
A management group in the Sovereign Landing Zone, beneath Landing zones, intended for workloads exposed to the internet that handle highly confidential data. It layers confidential computing controls for encryption in use on top of the Online policies.