This is the Trace Id: c4e0386b8eafdcbfb5375bb2140b71d4
Skip to main content Explore View all products (200+) Microsoft Foundry Azure Copilot GitHub Copilot Azure Kubernetes Service (AKS) Azure Cosmos DB Azure Database for PostgreSQL Azure Arc Microsoft Fabric Linux virtual machines in Azure Foundry Models Foundry Agent Service Foundry IQ Foundry Tools Foundry Control Plane Observability in Foundry Control Plane Azure OpenAI in Foundry Models Azure Speech in Foundry Tools Azure Machine Learning View all databases Azure Cosmos DB Azure DocumentDB Azure SQL Azure Database for PostgreSQL Azure Managed Redis Microsoft Fabric Azure Databricks Linux virtual machines in Azure Windows Server on Azure Azure Functions Azure Virtual Machine Scale Sets Azure API Management Azure Container Apps Azure Kubernetes Service (AKS) Azure Kubernetes Fleet Manager Azure Container Registry Azure Red Hat OpenShift Azure Container Instances Azure Container Storage Azure Arc Azure Local Microsoft Defender for Cloud Azure Monitor Microsoft Sentinel Azure Migrate View all solutions (40+) Cloud solutions for small and medium businesses Cloud migration and modernization center Data analytics for AI Azure Databases AI apps and agents Microsoft Marketplace Microsoft Sovereign Cloud AI apps and agents Responsible AI with Azure AI Infrastructure Data analytics for AI Machine learning operations (MLOps) Low-code application development on Azure Integration Services Serverless computing DevOps Migration and modernization center .NET apps migration Databases on Azure Linux on Azure Oracle on Azure SAP on the Microsoft Cloud Adaptive cloud High-performance computing (HPC) Infrastructure as a service (IaaS) Resiliency Azure Essentials Frontier Accelerate for Azure FinOps on Azure Microsoft Marketplace Azure pricing overview Create an Azure account Free Azure services Flexible purchase options Pricing calculator FinOps on Azure Maximize ROI from AI Azure savings plans Azure reservations Azure Hybrid Benefit Virtual Machines Azure SQL Microsoft Foundry Microsoft Fabric Azure Kubernetes Service (AKS) Microsoft Defender for Cloud View more Software Development Companies Microsoft Marketplace Find a partner Resources for Azure partners Get started with Azure Customer stories Analyst reports, white papers, and e-books Videos Learn more about cloud computing Documentation Explore Azure portal Developer resources Quickstart templates Resources for startups Developer community Students Azure for partners Blog Events and Webinars Learn Support Contact Sales Get started with Azure Sign in

Azure EnclavePREVIEW

Streamlines the deployment and management of isolated cloud environments for sensitive workloads across government and other regulated industries.
OVERVIEW

Designed to help reduce the time and complexity required for networking, governance, and monitoring

Managed infrastructure with built-in security controls helps streamline planning, configuration, and testing to provide isolated networking for sensitive workloads and data.
  • Designed to isolate your virtual networking infrastructure by default and includes controls intended to help ensure connections are explicitly configured and managed.
    A man sitting at a desk using a laptop.
  • Use policy controls within communities and enclaves to support consistent configuration and alignment with organizational compliance requirements.
    A woman using a touch screen.
  • Apply multiple security controls, including network segmentation, role-based access, and monitoring, to help protect workloads and simplify management.
Back to tabs
FEATURES

Explore capabilities built for sensitive and regulated workloads

Use Azure Enclave to establish isolated environments, apply policy controls, and manage secured networking for sensitive workloads.

Secured and isolated networking

Provides isolated networking configurations designed for sensitive workloads.

Connection management

Configure and manage connections between applications, users, and data using defined access controls.

Compliance and governance

Includes tools to support alignment with applicable standards including DoD IL5, IL6, and ICD 503 environments, with continuous monitoring and real-time logging.

Accelerate deployment of secured environments

Supports rapid deployment of secured environments using managed infrastructure and predefined architectural patterns.

Built-in observability

Enables robust security alerting, analytics, and centralized visibility into activity configuration, and system changes.

Custom workloads and service catalog

Create and deploy workloads using integrated Azure services, enabling tailored resource management and deployment to support a range of application scenarios.

Simplified cloud management

Manages networking, logging, and governance using integrated platform capabilities.

Defense-in-depth capabilities

Combine multiple controls, including network isolation, role-based access control, monitoring, and change approval, to support a layered approach to securing workloads and managing access.
Security

Embedded security and compliance

34,000
Full-time equivalent engineers dedicated to security initiatives at Microsoft.
15,000
Partners with specialized security expertise.
 
>100
Compliance certifications, including over 50 specific to global regions and countries.
A woman in a brown dress and a man sitting at a table talking.
Pricing

Pricing that gives you flexibility and control

You pay for:
  • The hours your enclaves are deployed
  • Your usage on the managed resources we deploy for you
  • Your workload resources (databases, web apps, virtual machines, etc.)
“By reducing complexity and accelerating mission readiness, this can streamline secured cloud solutions for public and private sector organizations.”
Brent Wodicka, Chief Technology Officer, Applied Information Sciences
FAQ

Frequently asked questions

  • Azure Enclave is a hub-and-spoke network architecture with network isolation and policy enforcement out of the box.
  • Azure Enclave creates a secured foundation so you can support efforts to meet organizational compliance requirements through consistent configuration and policy controls and deploy your workloads.
  • Azure Enclave uses a managed community-and-enclave model. A community provides shared network controls, and each enclave provides isolated workload boundaries. You connect approved endpoints with enclave connections, and Azure Enclave applies policy and routing controls across those paths. For architecture details, see What is Azure Enclave?
  • Azure Enclave pricing includes an hourly charge per enclave plus charges for the managed resources. The managed resources create the layers of secure enclave isolation and include Virtual WAN, Azure Firewall, virtual networks, and optional Log Analytics based on your deployment. For current rates, see Azure Enclave pricing.
  • Azure Enclave helps establish network boundaries designed for security and policy enforcement and separates workloads through controlled connectivity. It can reduce setup effort for regulated environments by using a known architecture and managed platform components. For more information, see Why use Azure Enclave?
  • Start with What is Azure Enclave?, review the learn Azure Enclave article, then create resources in a tutorial or sample templates to deploy reference architectures. Review the best practices article when you're ready to start planning a production design.
  • You can easily deploy customized individual components from the portal, but we also offer quickstart reference architectures.
  • Yes, communities and enclaves can exist in one subscription or in separate subscriptions within the same tenant. This allows separate organizations to pay for the resources associated with each enclave if that fits your use case.
  • Azure Enclave is available in the regions listed in the link below.
  • Azure Enclave includes new roles to help you manage your environments with least privileges. These roles include: owner, contributor, reader, and approver, scoped at the community or enclave level (e.g. “community owner”).
A woman sitting at a table using a laptop.
Next steps

Choose the Azure account that’s right for you

Pay as you go or try Azure free for up to 30 days.
A woman with curly hair wearing a green shirt.
Azure solutions

Azure cloud solutions

Solve your business problems with proven combinations of Azure cloud services, as well as sample architectures and documentation.
A man in a white jacket using a laptop.
Azure networking

Explore Azure networking and network security services

Discover how to connect, deliver, and help protect both cloud-native and hybrid applications using fully managed services in Azure.