Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Microsoft completed the EU Data Boundary for the Microsoft Cloud on February 26, 2025. The project, begun in January 2023, commits supported Microsoft 365, Dynamics 365, Power Platform and most Azure services to store and process covered customer data and pseudonymized personal data within European Union (EU) and European Free Trade Association (EFTA) regions. It is a major data-residency change, but it is not the same as an EU-owned, EU-operated cloud that eliminates every foreign legal or operational dependency.
Microsoft has continued expanding a broader Microsoft Sovereign Cloud portfolio through 2026, adding public-cloud controls, private and local deployments, disconnected operation and local AI options.
What Microsoft actually finalized
The completed project was the EU Data Boundary for the Microsoft Cloud, not a newly independent European cloud company or a separate hyperscale network. Microsoft announced completion on February 26, 2025, after starting the project in January 2023. Its stated boundary covers EU and EFTA regions for supported services and covered data categories. Microsoft’s announcement is available at Microsoft’s EU Data Boundary update.
The EU has 27 member states. EFTA adds Iceland, Liechtenstein, Norway and Switzerland. “Europe” in Microsoft marketing can describe a wider set of regions and commitments, so procurement documents should use the specific EU/EFTA boundary and the relevant service terms.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
What the boundary addresses
- Storage of covered customer data in EU/EFTA regions.
- Processing of covered customer data in those regions for supported services.
- Storage and processing commitments for certain pseudonymized personal data.
- More transparency about how Microsoft handles data, access and service operations.
What it does not automatically settle
- Every Azure service or feature: Microsoft says “most Azure services,” not all of them.
- Professional-services data, support tickets, diagnostic and telemetry data, identity metadata, billing records, backups or disaster-recovery copies in every scenario.
- Data flows created by marketplace products, third-party connectors, analytics tools or cross-region replication.
- Microsoft’s corporate jurisdiction, administrator-access model, foreign legal demands or portability away from Microsoft.
Microsoft’s EU Data Boundary FAQ says service-specific requirements and exclusions apply. A buyer should therefore verify each data category and service rather than treating the boundary as universal isolation.
Which products are covered?
Microsoft identifies Microsoft 365, Dynamics 365, Power Platform and most Azure services as core covered services. Coverage remains service-specific. A tenant can have its primary content in Europe while a particular control plane, support interaction, log, integration or third-party service follows different rules.
EU/EFTA inventory checklist
- List every Microsoft SaaS product, Azure resource, identity dependency and security tool in the workload.
- Confirm each service’s EU/EFTA regional availability and EU Data Boundary status.
- Identify global-control-plane, support, logging, backup and disaster-recovery behavior.
- Review professional-services-data terms separately from customer-content terms.
- Trace marketplace products, external connectors and replication paths.
- Test failover and incident-support procedures, including where personnel and telemetry may be involved.
Residency is only one part of sovereignty
Data residency answers where data is stored or processed. Sovereignty is broader:
Rank #2
| Dimension | Question for a buyer |
|---|---|
| Operational | Who can administer systems, approve access and provide remote support? |
| Technological | Can the workload continue without a foreign control plane or proprietary service? |
| Legal | Which corporate jurisdictions and legal processes could affect access? |
| Cryptographic | Who controls the keys, and can the provider decrypt data? |
| Infrastructure | Who owns and physically controls servers, networks and facilities? |
Microsoft’s Sovereign Public Cloud documentation presents residency, confidential computing, customer-managed keys, hardware security modules, policy guardrails and European personnel controls as separate capabilities.
Does EU storage remove exposure to non-European law?
No single residency commitment can establish that conclusion. Microsoft says covered data for supported services is stored and processed within EU/EFTA boundaries, but physical location does not by itself determine corporate control, administrator access, encryption-key ownership or the reach of a government demand.
Organizations should examine Microsoft’s data-processing terms, service-specific boundary documentation, support model, subcontractors, access controls and customer-managed-key options. Microsoft’s Defending Your Data Initiative includes a commitment to challenge certain government requests where Microsoft has a lawful basis. That is a legal and policy commitment, not proof that foreign-access risk is impossible.
Rank #3
How Microsoft’s sovereign-cloud portfolio has expanded
Microsoft now describes sovereignty as a portfolio rather than one product. Its overview separates Sovereign Public Cloud, Sovereign Private Cloud, Azure Local, Microsoft 365 Local, local AI and governance capabilities: Microsoft Sovereign Cloud overview.
Sovereign Public Cloud
Sovereign Public Cloud layers controls onto existing Microsoft public-cloud regions. Microsoft lists the EU Data Boundary, Advanced Data Residency for Microsoft 365, confidential computing, customer-controlled or customer-managed keys, hardware security-module integration, policy-as-code, sovereign landing zones and Data Guardian controls for remote access. The model is intended to retain public-cloud scale and managed services while adding sovereignty controls; it is not presented as a wholly separate hyperscale cloud.
Recommended Free Tools
Microsoft says these capabilities can operate across existing European regions, although a customer may still need configuration changes, service migrations or architecture work. Its Switzerland update explains that approach at Microsoft’s European sovereignty update.
Rank #4
Sovereign Private Cloud and Azure Local
Private and local deployments target workloads that need stronger isolation, customer-controlled infrastructure or operation when connectivity is restricted. Microsoft’s February 2026 announcement covers disconnected Azure Local, Microsoft 365 Local and local AI capabilities: disconnected sovereign-cloud capabilities. In April 2026, Microsoft said Azure Local could scale to thousands of servers in a single sovereign environment: Azure Local scale announcement.
Disconnected operation is not simply “Azure in a box.” It can reduce access to cloud-managed services, impose different update and support procedures, limit features or versions and place more security and recovery responsibility on local operators.
Public versus private or local deployment
| Requirement | Sovereign Public Cloud | Sovereign Private/Local Cloud |
|---|---|---|
| EU/EFTA residency | Yes, for supported services and data | Yes, within the customer’s deployment boundary |
| Hyperscale managed services | Stronger | More limited or workload-dependent |
| Customer infrastructure control | Lower | Higher |
| Disconnected operation | Generally not the default | Designed for disconnected or intermittent connectivity |
| Operational burden | Lower | Higher: hardware, capacity, patching and local staff |
| Migration effort | Often lower | Often higher |
| Best fit | Regulated enterprise workloads needing scale | Critical, isolated or disconnected workloads |
What changed for customers
- Covered customer data can be kept within EU/EFTA regions under Microsoft’s boundary commitments.
- European public-sector and regulated-industry procurement can reference a clearer residency framework.
- Organizations can combine existing Microsoft services with confidential computing, key-management and policy controls.
- Customers with extreme isolation requirements have additional Azure Local and Microsoft 365 Local choices.
These benefits do not remove the need to configure the correct tenant and region, verify logging and support paths, review integrations and confirm service availability. The boundary also does not make a Microsoft workload portable by itself.
Best Value
Does the EU Data Boundary cost extra?
Microsoft’s FAQ says customers can use services meeting EU data-residency requirements without a price increase attributable to the EU Data Boundary. That statement applies to the residency commitment, not to every sovereignty feature.
Customer-managed keys, hardware security modules, Azure Local hardware, private deployments, consulting, support, licensing and operations can add cost. Azure consumption remains service-, region-, capacity-, storage-, bandwidth- and usage-based. Microsoft publishes general information at Azure pricing; a meaningful estimate requires a defined workload.
Decision guide for procurement teams
Microsoft’s public-cloud approach may fit when
- EU/EFTA residency is the principal requirement.
- The organization already relies on Azure, Microsoft 365, Dynamics 365 or Power Platform.
- Public-cloud scale and managed services matter more than provider independence.
- Confidential computing, customer-managed keys and policy guardrails satisfy the control objectives.
Evaluate Azure Local or private sovereign options when
- Systems must run inside a customer-controlled operational boundary.
- Connectivity may be unavailable or deliberately restricted.
- Mission-critical classification justifies local infrastructure and staffing.
- The organization can manage hardware, lifecycle, patching, capacity and recovery.
Compare European-owned providers when
- Procurement requires EU ownership or control.
- Reducing dependence on U.S.-based hyperscalers is a decisive objective.
- Foreign-government access risk outweighs the breadth of hyperscale services.
- The workload can tolerate a smaller service catalog or fewer regions.
Alternatives and the sovereignty trade-off
AWS, Google Cloud and European providers address different thresholds. AWS offers a competing European Sovereign Cloud. Google Cloud describes its approach at Google Cloud Sovereign Cloud. OVHcloud (site), IONOS Cloud (site) and STACKIT (site) offer European-headquartered options with different service breadth and geographic reach. French national partnership models include Bleu and S3NS.
The European Commission said in June 2026 that AWS and Microsoft Azure were preliminarily considered important cloud gateways under the Digital Markets Act process; this was not a final designation. See the Commission announcement.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →For maximum portability, buyers should favor open standards, containerized applications, independent identity where practical, customer-controlled keys, documented export paths and a tested multi-cloud or exit plan.
Timeline
| Date | Development |
|---|---|
| January 2023 | Microsoft began the EU Data Boundary project. |
| February 26, 2025 | Microsoft announced completion of the EU Data Boundary. |
| June 16, 2025 | Microsoft announced broader Sovereign Public Cloud and Sovereign Private Cloud strategies in Europe. |
| November 2025 | Microsoft expanded European sovereignty capabilities, including AI processing and private-cloud options. |
| February 24, 2026 | Microsoft announced disconnected Azure Local, Microsoft 365 Local and local AI capabilities. |
| April 27, 2026 | Microsoft announced Azure Local scaling to thousands of servers per sovereign environment. |
| April 29, 2026 | Microsoft reaffirmed completion of the EU Data Boundary and described its wider portfolio. |
| June 25, 2026 | The European Commission published a preliminary DMA position on major cloud gateways. |
The Bottom Line
Microsoft finished its EU Data Boundary in February 2025, materially strengthening European residency for supported services and data. It is sufficient for many residency-led compliance requirements, but it does not by itself deliver EU ownership, complete operational independence or immunity from non-EU legal influence. Buyers should match the deployment model—public, private, local or disconnected—to the sovereignty risk they actually need to control.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




