केवल यूरोपीय विकल्प Microsoft Azure.
Microsoft Azure is the cloud most often defended with the words "but we already use Microsoft for everything." That defence does not survive a Schrems II analysis: Microsoft Corporation is a US company, every Azure subsidiary is US-controlled, and Microsoft has explicitly acknowledged in court (Microsoft Ireland, 2018) that it would comply with valid US legal process for data anywhere globally - which is precisely what the CLOUD Act later codified. The "Microsoft Cloud for Sovereignty" and Bleu (Microsoft × Capgemini × Orange) initiatives are interesting but technology-licensed from a US parent. For genuine EU sovereignty, you exit. Below is the map.
- प्रदाता
- Microsoft Azure
- मुख्यालय
- Redmond, WA
- न्यायाधिकार
- United States
- विधिक शासन
- CLOUD Act, FISA 702, EO 12333
"EU क्षेत्र" संप्रभुता नहीं है। चार प्रश्न इसे तय करते हैं।
डेटा रेजिडेंसी आपको बताती है कि बिट्स कहाँ स्थित हैं। सॉवरेनिटी आपको बताती है कि कौन-सी लीगल सिस्टम एक्सेस के लिए मजबूर कर सकती है। जवाब चारों पर सही होना चाहिए - नहीं तो स्टैक सॉवरेन नहीं है।
- रेजीडेंसी
-
डेटा भौतिक रूप से कहाँ संग्रहीत है?
"cloud में" नहीं - बल्कि कौन सा datacenter, किस देश में, किस jurisdiction के अंतर्गत।
- सबप्रोसेसर
-
आपके डेटा पथ में और कौन है?
हर विक्रेता जो डेटा को छूता है: CDN, ईमेल रिले, त्रुटि ट्रैकर, एनालिटिक्स पाइप।
- न्यायाधिकार
-
किसके कानून प्रकटीकरण के लिए मजबूर कर सकते हैं?
US-headquartered प्रोवाइडर FISA 702 और CLOUD Act के अंतर्गत आता है - भले ही डेटा Frankfurt में हो।
- कुंजी अभिरक्षा
-
वास्तव में एन्क्रिप्शन कुंजियाँ कौन रखता है?
अगर cloud provider के पास data और keys दोनों हैं, तो data उनके द्वारा पढ़ा जा सकता है - किसी भी DPA के बावजूद।
न्यायाधिकार और कुंजी अभिरक्षा पर असफल।
EU डेटा, अमेरिकी मुख्यालय वाली मूल कंपनी, डिफ़ॉल्ट पथ में अमेरिकी सबप्रोसेसर, प्रदाता-प्रबंधित कुंजियाँ।
सभी चारों पर सफल।
EU में होस्टेड EU मुख्यालय वाले बुनियादी ढांचे पर। डिफ़ॉल्ट पथ में शून्य अमेरिकी सबप्रोसेसर। ग्राहक-धारित या EU-KMS कुंजियाँ। आपके अनुच्छेद 28 DPA में नाम से सूचीबद्ध।
टीमें क्यों बाहर निकल रही हैं Microsoft Azure
Azure exits typically come from one of three triggers: a public-sector tender that explicitly excludes US-jurisdiction processors, a healthcare or financial services audit that flagged Microsoft 365 + Azure as a single concentration risk under DORA, or a CISO who calculated that the licence true-up costs and "free" Azure credits actually translate to vendor lock-in worth six figures. The Azure ecosystem has tighter coupling than AWS - Active Directory, Office 365, Defender, Sentinel are typically all in the mix - which makes the migration more invasive than its AWS equivalent. It is still doable; we have done it.
Microsoft Azure सेवाएँ और उनके केवल-EU समकक्ष
माइग्रेशन "एक बॉक्स को दूसरे से बदलना" नहीं है। नीचे दी गई मैपिंग वह है जो हम निम्न को छोड़ने वाले ग्राहकों के लिए चलाते हैं: Microsoft Azure Schrems II आधार पर - पूरी EU jurisdiction, data path में कोई US parent नहीं।
Azure Virtual Machines
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. Debian या Ubuntu पर KVM virtual machines, Terraform से provision और Ansible से configure किए गए।
- इंजीनियरिंग टिप्पणी
- IaaS migration सीधा है; Windows licensing का हिस्सा ज़्यादा सोच-विचार माँगता है (BYOL या जहाँ संभव हो Linux पर move करना)।
Azure Blob Storage
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. MinIO या Ceph RGW, S3-compatible।
- इंजीनियरिंग टिप्पणी
- S3-compatible EU storage ही migration target है; SDK में बदलाव न्यूनतम हैं।
Azure SQL Database
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. failover के लिए Patroni के साथ PostgreSQL या MySQL, और point-in-time recovery के लिए pgBackRest.
- इंजीनियरिंग टिप्पणी
- Azure SQL (T-SQL flavour) से schema porting सबसे लंबा single task है; AWS SCT या pgloader जैसे tools मदद करते हैं। यह अक्सर ORM choices को फिर से देखने का अच्छा मौका होता है।
Azure Front Door / CDN
- इसके बजाय हम क्या चलाते हैं
- हम आपके लिए EU CDN implement और operate करते हैं: Bunny.net या KeyCDN, आपके origin पर Nginx और Varnish caching के साथ।
- इंजीनियरिंग टिप्पणी
- CDN उन कुछ लेयर्स में से एक है जिन्हें हम खुद नहीं चलाते। हम EU प्रोवाइडर चुनते हैं, cache headers, purge strategy और origin shielding कॉन्फ़िगर करते हैं, और इसे मैनेज्ड सर्विस के हिस्से के रूप में ऑपरेट करते हैं।
Azure DNS
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. PowerDNS या Knot, authoritative, DNSSEC signed.
- इंजीनियरिंग टिप्पणी
- Zones को standard zone files के रूप में export और import किया जाता है, इसलिए यह migration का सबसे कम घटनापूर्ण हिस्सा होता है। TTLs को एक हफ्ते पहले कम कर दें।
AKS (managed Kubernetes)
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. Debian या Talos पर Kubernetes, Cilium networking और certificates के लिए cert-manager के साथ।
- इंजीनियरिंग टिप्पणी
- Helm charts और YAML आसानी से transfer हो जाते हैं; Azure-specific addons (Application Gateway Ingress, Azure CNI) को standard equivalents से replace करना होगा।
Azure Functions
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. आपके Kubernetes cluster पर Knative या OpenFaaS।
- इंजीनियरिंग टिप्पणी
- ज्यादातर Azure Functions workloads Knative चलाने वाले एक छोटे EU Kubernetes cluster में फिट हो जाते हैं।
Azure Active Directory / Entra ID
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. identity provider के रूप में Keycloak या Authentik, OIDC और SAML के साथ।
- इंजीनियरिंग टिप्पणी
- सबसे कठिन सिंगल माइग्रेशन। 3 महीने की parallel-run विंडो की योजना बनाएं। SaaS में SSO integrations को दोबारा मैप करने की जरूरत होती है।
Azure Service Bus / Event Grid
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. delivery guarantees के अनुसार RabbitMQ, NATS, या Redis Streams.
- इंजीनियरिंग टिप्पणी
- EU sovereign space में managed queueing options सीमित हैं; self-managed मानक है।
Azure Monitor / Application Insights
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. Prometheus, Grafana, Loki और Tempo, OpenTelemetry के साथ जुड़े हुए.
- इंजीनियरिंग टिप्पणी
- OpenTelemetry instrumentation application code के लिए swap को मैकेनिकल बना देता है।
Azure Cosmos DB
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. MongoDB replica sets, या JSONB के साथ PostgreSQL जहां document model दिखने से हल्का है।
- इंजीनियरिंग टिप्पणी
- ग्लोबल मल्टी-रीजन एक्टिव-एक्टिव के लिए कोई 1:1 रिप्लेसमेंट नहीं है; यदि आपके workload को वास्तव में यह pattern चाहिए, तो बातचीत अलग होगी।
Defender / Sentinel (security)
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. OWASP Core Rule Set के साथ Coraza या ModSecurity, साथ ही behavioural blocking के लिए CrowdSec।
- इंजीनियरिंग टिप्पणी
- CrowdSec का headquarters FR में है और यह SIEM/IDS space में लगातार competitive होता जा रहा है।
Key Vault
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. HashiCorp Vault या Infisical, self-hosted, automatic lease rotation के साथ।
- इंजीनियरिंग टिप्पणी
- Vault production-grade sovereign जवाब है; हम इसे क्लाइंट्स के लिए ऑपरेट करते हैं।
Microsoft 365 (email, Teams, OneDrive)
- इसके बजाय हम क्या चलाते हैं
- Binadit Managed Cloud Platform. DKIM, SPF और DMARC के साथ Postfix, और फ़िल्टरिंग के लिए Rspamd.
- इंजीनियरिंग टिप्पणी
- अक्सर यह infrastructure migration से ज्यादा कठिन political बातचीत होती है। अक्सर इसे migrate करने के बजाय documented exposure के साथ M365 पर ही रखा जाता है।
हम कैसे माइग्रेट करते हैं Microsoft Azure
एक सामान्य mid-market माइग्रेशन तीन फेज़ में चलता है। नीचे दिए गए आंकड़े 6-10 लोगों की इंजीनियरिंग टीम और मध्यम रूप से कॉम्प्लेक्स एप्लिकेशन स्टैक को मानकर दिए गए हैं।
-
Weeks 1-3
Audit & ID-mapping
Inventory Azure services, Entra ID dependencies, SSO integrations and licensing. The identity layer is the longest tail. Output: phased plan with the SSO migration scoped separately.
-
Weeks 3-6
Edge, monitoring, soft dependencies
Replace Front Door, Azure DNS, App Insights and Blob Storage. Pre-stage EU compute and replicate database. Move CI/CD off Azure DevOps if applicable.
-
Weeks 6-18
Compute, DB, identity cutover
AKS workloads to managed EU K8s. SQL Database to PostgreSQL with logical replication for live cutover. Identity migration with parallel-run; cut SSO over per application.
5-year TCO on Azure exits we have run: typically 25-45% cheaper, with the largest savings coming from licence true-up avoidance and bandwidth/egress. Bear in mind: if your team uses Microsoft 365 and is staying on it, the identity-layer migration only partially decouples - that decision belongs at board level.
अक्सर पूछे जाने वाले प्रश्न
Does Microsoft Cloud for Sovereignty solve the Schrems II problem?
What about Bleu?
Can we leave Azure but keep Microsoft 365?
How does this affect our Microsoft Enterprise Agreement?
Is Active Directory replaceable in practice?
How long does an Azure exit take?
अपनी निकास योजना बनाएँ Microsoft Azure.
30-मिनट का स्कोपिंग कॉल। हम आपके स्टैक को केवल-EU विकल्पों के विरुद्ध मैप करते हैं, माइग्रेशन प्रयास का अनुमान लगाते हैं, और आपको बताते हैं कि क्या यह सही निर्णय है।