Europa-only Alternative zu Microsoft Azure.

Microsoft Azure is the cloud most often defended with the words "but we already use Microsoft for everything." That defence does not survive a Schrems II analysis: Microsoft Corporation is a US company, every Azure subsidiary is US-controlled, and Microsoft has explicitly acknowledged in court (Microsoft Ireland, 2018) that it would comply with valid US legal process for data anywhere globally - which is precisely what the CLOUD Act later codified. The "Microsoft Cloud for Sovereignty" and Bleu (Microsoft × Capgemini × Orange) initiatives are interesting but technology-licensed from a US parent. For genuine EU sovereignty, you exit. Below is the map.

United States Ersatz-Stack, ausschließlich EU 14 Dienste zugeordnet
Anbieter
Microsoft Azure
Hauptsitz
Redmond, WA
Rechtsmacht
United States
Rechtsregime
CLOUD Act, FISA 702, EO 12333

"EU-Region" ist keine Souveränität. Vier Fragen entscheiden.

Data-Residency sagt, wo die Bits liegen. Souveränität sagt, welches Rechtssystem Zugriff erzwingen kann. Die Antwort muss auf allen vier Punkten halten, sonst ist der Stack nicht souverän.

Residenz

Wo sind die Daten physisch gespeichert?

Nicht "in der Cloud": welches Rechenzentrum, in welchem Land, unter welcher Jurisdiktion.

Subprozessoren

Wer ist sonst noch in Ihrem Datenpfad?

Jeder Anbieter, der die Daten berührt: das CDN, das E-Mail-Relay, der Error-Tracker, die Analytics-Pipeline.

Rechtsmacht

Wessen Gesetze können die Offenlegung erzwingen?

Ein Anbieter mit US-Hauptsitz untersteht FISA 702 und dem CLOUD Act, auch wenn die Bits in Frankfurt liegen.

Schlüsselverwahrung

Wer hält tatsächlich die Verschlüsselungsschlüssel?

Wenn der Cloud-Anbieter sowohl die Daten als auch die Schlüssel hält, sind die Daten für ihn lesbar, unabhängig von jedem AVV.

Erfüllt nicht AWS · Azure · GCP · EU-Region

Scheitert an Rechtsmacht und Schlüsselverwahrung.

EU-Daten, US-Mutterkonzern, US-Subprozessoren im Standardpfad, vom Anbieter verwaltete Schlüssel.

Erfüllt Binadit Managed Stack

Besteht in allen vier Punkten.

EU-gehostet auf Infrastruktur mit EU-Hauptsitz. Null US-Subprozessoren im Standardpfad. Kunden- oder EU-KMS-Schlüssel. Namentlich in Ihrer Artikel-28-AVV aufgeführt.

Warum Teams aussteigen Microsoft Azure

Azure exits typically come from one of three triggers: a public-sector tender that explicitly excludes US-jurisdiction processors, a healthcare or financial services audit that flagged Microsoft 365 + Azure as a single concentration risk under DORA, or a CISO who calculated that the licence true-up costs and "free" Azure credits actually translate to vendor lock-in worth six figures. The Azure ecosystem has tighter coupling than AWS - Active Directory, Office 365, Defender, Sentinel are typically all in the mix - which makes the migration more invasive than its AWS equivalent. It is still doable; we have done it.

Microsoft Azure Dienste und ihre EU-only Äquivalente

Eine Migration ist nicht "eine Box gegen eine andere tauschen". Die Zuordnung unten ist das, was wir für Kunden ausführen, die Folgendes verlassen: Microsoft Azure auf Grundlage von Schrems II: vollständige EU-Jurisdiktion, kein US-Mutterkonzern im Datenpfad.

Azure Virtual Machines

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. KVM-VMs auf Debian oder Ubuntu, provisioniert mit Terraform und konfiguriert mit Ansible.
Engineering-Hinweis
Die IaaS-Migration ist unkompliziert; das Kapitel Windows-Lizenzierung erfordert mehr Überlegung (BYOL oder Umstieg auf Linux, wo möglich).

Azure Blob Storage

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. MinIO oder Ceph RGW, S3-kompatibel.
Engineering-Hinweis
S3-kompatibler EU-Storage ist das Migrationsziel; SDK-Änderungen sind minimal.

Azure SQL Database

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. PostgreSQL oder MySQL mit Patroni für Failover und pgBackRest für Point-in-Time Recovery.
Engineering-Hinweis
Die Schema-Portierung von Azure SQL (T-SQL-Dialekt) ist die zeitaufwendigste Einzelaufgabe; Tools wie AWS SCT oder pgloader helfen dabei. Oft ein guter Zeitpunkt, um die ORM-Wahl zu überdenken.

Azure Front Door / CDN

Was wir stattdessen betreiben
Wir implementieren und betreiben ein EU-CDN für Sie: Bunny.net oder KeyCDN, mit Nginx- und Varnish-Caching an Ihrem Origin.
Engineering-Hinweis
Ein CDN ist eine der wenigen Schichten, die wir nicht selbst betreiben. Wir wählen den EU-Anbieter aus, konfigurieren Cache-Header, Purge-Strategie und Origin Shielding und betreiben es als Teil des Managed Service.

Azure DNS

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. PowerDNS oder Knot, autoritativ, DNSSEC-signiert.
Engineering-Hinweis
Zonen werden als Standard-Zonendateien exportiert und importiert, das ist meist der unspektakulärste Teil einer Migration. Senken Sie die TTLs eine Woche im Voraus.

AKS (managed Kubernetes)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Kubernetes auf Debian oder Talos, mit Cilium-Networking und cert-manager für Zertifikate.
Engineering-Hinweis
Helm Charts und YAML lassen sich sauber übertragen; Azure-spezifische Addons (Application Gateway Ingress, Azure CNI) müssen durch Standardäquivalente ersetzt werden.

Azure Functions

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Knative oder OpenFaaS auf Ihrem Kubernetes-Cluster.
Engineering-Hinweis
Die meisten Azure-Functions-Workloads passen auf einen kleinen EU-Kubernetes-Cluster mit Knative.

Azure Active Directory / Entra ID

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Keycloak oder Authentik als Identity Provider, mit OIDC und SAML.
Engineering-Hinweis
Die schwierigste Einzelmigration. Planen Sie ein Parallelbetriebsfenster von 3 Monaten ein. SSO-Integrationen über SaaS-Dienste hinweg müssen neu zugeordnet werden.

Azure Service Bus / Event Grid

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. RabbitMQ, NATS oder Redis Streams, je nach Zustellgarantien.
Engineering-Hinweis
Managed-Queueing-Optionen im EU-souveränen Raum sind begrenzt; Self-Managed ist Standard.

Azure Monitor / Application Insights

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Prometheus, Grafana, Loki und Tempo, verbunden mit OpenTelemetry.
Engineering-Hinweis
OpenTelemetry-Instrumentierung macht den Wechsel für den Anwendungscode mechanisch.

Azure Cosmos DB

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. MongoDB Replica Sets, oder PostgreSQL mit JSONB, wo das Dokumentenmodell dünner ist, als es aussieht.
Engineering-Hinweis
Kein 1:1-Ersatz für globales Multi-Region-Active-Active; wenn Ihr Workload dieses Muster wirklich benötigt, verläuft das Gespräch anders.

Defender / Sentinel (security)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Coraza oder ModSecurity mit dem OWASP Core Rule Set, plus CrowdSec für verhaltensbasierte Blockierung.
Engineering-Hinweis
CrowdSec hat seinen Hauptsitz in FR und wird im SIEM/IDS-Bereich zunehmend wettbewerbsfähiger.

Key Vault

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. HashiCorp Vault oder Infisical, self-hosted, mit automatischer Lease-Rotation.
Engineering-Hinweis
Vault ist die produktionsreife souveräne Antwort; wir betreiben sie für Kunden.

Microsoft 365 (email, Teams, OneDrive)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Postfix mit DKIM, SPF und DMARC, sowie Rspamd zum Filtern.
Engineering-Hinweis
Oft die schwierigere politische Diskussion als die Infrastrukturmigration selbst. Wird häufig mit dokumentierter Risikolage bei M365 belassen, statt migriert.

Wie wir migrieren von Microsoft Azure

Eine typische Mittelstand-Migration läuft in drei Phasen. Die Zahlen unten gehen von einem 6-10-köpfigen Engineering-Team und einem mäßig komplexen Anwendungs-Stack aus.

  1. Weeks 1-3

    Audit & ID-mapping

    Inventory Azure services, Entra ID dependencies, SSO integrations and licensing. The identity layer is the longest tail. Output: phased plan with the SSO migration scoped separately.

  2. Weeks 3-6

    Edge, monitoring, soft dependencies

    Replace Front Door, Azure DNS, App Insights and Blob Storage. Pre-stage EU compute and replicate database. Move CI/CD off Azure DevOps if applicable.

  3. Weeks 6-18

    Compute, DB, identity cutover

    AKS workloads to managed EU K8s. SQL Database to PostgreSQL with logical replication for live cutover. Identity migration with parallel-run; cut SSO over per application.

5-year TCO on Azure exits we have run: typically 25-45% cheaper, with the largest savings coming from licence true-up avoidance and bandwidth/egress. Bear in mind: if your team uses Microsoft 365 and is staying on it, the identity-layer migration only partially decouples - that decision belongs at board level.

Does Microsoft Cloud for Sovereignty solve the Schrems II problem?
It improves the documentation story but does not change the underlying jurisdiction: Microsoft Corporation remains the parent. For workloads where the analysis turns on parent-jurisdiction (i.e. most regulated workloads after Schrems II), it is not sufficient on its own.
What about Bleu?
Licensed sovereign offerings, where an EU entity operates US technology under licence, are pseudo-sovereign - operated by EU-headquartered entities under licence from a US technology partner. They can satisfy specific regulatory requirements (notably the French SecNumCloud certification for Bleu) but inherit a stack they cannot independently maintain. For most buyers, a clean EU-native stack is the architecturally simpler answer.
Can we leave Azure but keep Microsoft 365?
Yes, and many of our clients run that hybrid. The trade-off is that personal data flowing through M365 (email content, OneDrive files, Teams chat) remains under Microsoft processing. Document it in your DPA, apply supplementary measures (encryption at rest with EU-held keys for sensitive folders), and keep customer-data infrastructure on the sovereign stack.
How does this affect our Microsoft Enterprise Agreement?
Existing EAs typically have annual or multi-year terms; the migration target is to stop the next renewal or right-size it, not to break the current contract. Your account manager will offer concessions when they hear "we are evaluating sovereign alternatives." Use that.
Is Active Directory replaceable in practice?
Replaceable in stages. Keycloak handles OIDC/SAML/SCIM well; for Windows-domain authentication on physical desktops, Samba 4 with FreeIPA is the established open-source path. The transition typically runs alongside a "modern workplace" simplification - fewer per-app SSOs, more standard OIDC.
How long does an Azure exit take?
For a mid-size workload (50-200 VMs, 1-2 SQL DBs, AKS, Entra ID): 16-24 weeks elapsed time. With a managed-infrastructure partner driving the choreography: 10-16 weeks. The identity layer is the schedule risk, not the compute.

Plane deinen Exit von Microsoft Azure.

30-minütiges Scoping-Gespräch. Wir bilden Ihren Stack auf EU-only Alternativen ab, schätzen den Migrationsaufwand und sagen Ihnen, ob es die richtige Entscheidung ist.