This is the Trace Id: c9297132020375a0a3fb58016c48c47e
Skip to main content
Azure

Azure EnclavePREVIEW

Streamlines the deployment and management of isolated cloud environments for sensitive workloads across government and other regulated industries. 
OVERVIEW

Designed to help reduce the time and complexity required for networking, governance, and monitoring

Managed infrastructure with built-in security controls helps streamline planning, configuration, and testing to provide isolated networking for sensitive workloads and data.
  • Designed to isolate your virtual networking infrastructure by default and includes controls intended to help ensure connections are explicitly configured and managed.
    A man sitting at a desk using a laptop.
  • Use policy controls within communities and enclaves to support consistent configuration and alignment with organizational compliance requirements.
    A woman using a touch screen.
  • Apply multiple security controls, including network segmentation, role-based access, and monitoring, to help protect workloads and simplify management.
Back to tabs
FEATURES

Explore capabilities built for sensitive and regulated workloads

Use Azure Enclave to establish isolated environments, apply policy controls, and manage secured networking for sensitive workloads.

Secured and isolated networking

Provides isolated networking configurations designed for sensitive workloads.

Connection management

Configure and manage connections between applications, users, and data using defined access controls.

Compliance and governance

Includes tools to support alignment with applicable standards including DoD IL5, IL6, and ICD 503 environments, with continuous monitoring and real-time logging.

 Accelerate deployment of secured environments

Supports rapid deployment of secured environments using managed infrastructure and predefined architectural patterns.

Built-in observability

Enables robust security alerting, analytics, and centralized visibility into activity configuration, and system changes.

Custom workloads and service catalog

Create and deploy workloads using integrated Azure services, enabling tailored resource management and deployment to support a range of application scenarios.

Simplified cloud management

Manages networking, logging, and governance using integrated platform capabilities.

Defense-in-depth capabilities

Combine multiple controls, including network isolation, role-based access control, monitoring, and change approval, to support a layered approach to securing workloads and managing access.
Security

Embedded security and compliance

34,000
Full-time equivalent engineers dedicated to security initiatives at Microsoft.
15,000
Partners with specialized security expertise.
 
>100
Compliance certifications, including over 50 specific to global regions and countries.
A woman in a brown dress and a man sitting at a table talking.
Pricing

Pricing that gives you flexibility and control

You pay for:
  • The hours your enclaves are deployed
  • Your usage on the managed resources we deploy for you
  • Your workload resources (databases, web apps, virtual machines, etc.)
“By reducing complexity and accelerating mission readiness, this can streamline secured cloud solutions for public and private sector organizations.”
Brent Wodicka, Chief Technology Officer, Applied Information Sciences
FAQ

Frequently asked questions

  • Azure Enclave is a hub-and-spoke network architecture with network isolation and policy enforcement out of the box.  
  • Azure Enclave creates a secured foundation so you can support efforts to meet organizational compliance requirements through consistent configuration and policy controls and deploy your workloads.
  • Azure Enclave uses a managed community-and-enclave model. A community provides shared network controls, and each enclave provides isolated workload boundaries. You connect approved endpoints with enclave connections, and Azure Enclave applies policy and routing controls across those paths. For architecture details, see What is Azure Enclave?
  • Azure Enclave pricing includes an hourly charge per enclave plus charges for the managed resources. The managed resources create the layers of secure enclave isolation and include Virtual WAN, Azure Firewall, virtual networks, and optional Log Analytics based on your deployment. For current rates, see Azure Enclave pricing.
  • Azure Enclave helps establish network boundaries designed for security and policy enforcement and separates workloads through controlled connectivity. It can reduce setup effort for regulated environments by using a known architecture and managed platform components. For more information, see Why use Azure Enclave?
  • Start with What is Azure Enclave?, review the learn Azure Enclave article, then create resources in a tutorial or sample templates to deploy reference architectures. Review the best practices article when you're ready to start planning a production design.
  • You can easily deploy customized individual components from the portal, but we also offer quickstart reference architectures.
  • Yes, communities and enclaves can exist in one subscription or in separate subscriptions within the same tenant. This allows separate organizations to pay for the resources associated with each enclave if that fits your use case.
  • Azure Enclave is available in the regions listed in the link below.
  • Azure Enclave includes new roles to help you manage your environments with least privileges. These roles include: owner, contributor, reader, and approver, scoped at the community or enclave level (e.g. “community owner”).
A woman sitting at a table using a laptop.
Next steps

Choose the Azure account that’s right for you

Pay as you go or try Azure free for up to 30 days.
A woman with curly hair wearing a green shirt.
Azure solutions

Azure cloud solutions

Solve your business problems with proven combinations of Azure cloud services, as well as sample architectures and documentation.
A man in a white jacket using a laptop.
Azure networking

Explore Azure networking and network security services

Discover how to connect, deliver, and help protect both cloud-native and hybrid applications using fully managed services in Azure.