Europees-only alternatief voor Microsoft Azure.

Microsoft Azure is the cloud most often defended with the words "but we already use Microsoft for everything." That defence does not survive a Schrems II analysis: Microsoft Corporation is a US company, every Azure subsidiary is US-controlled, and Microsoft has explicitly acknowledged in court (Microsoft Ireland, 2018) that it would comply with valid US legal process for data anywhere globally - which is precisely what the CLOUD Act later codified. The "Microsoft Cloud for Sovereignty" and Bleu (Microsoft × Capgemini × Orange) initiatives are interesting but technology-licensed from a US parent. For genuine EU sovereignty, you exit. Below is the map.

United States Vervangende stack, uitsluitend EU 14 diensten in kaart gebracht
Leverancier
Microsoft Azure
Hoofdkantoor
Redmond, WA
Rechtsmacht
United States
Wettelijk regime
CLOUD Act, FISA 702, EO 12333

"EU-regio" is geen soevereiniteit. Vier vragen bepalen het.

Dataresidentie zegt waar de bits staan. Soevereiniteit zegt welk rechtssysteem toegang kan afdwingen. Het antwoord moet op alle vier standhouden, anders is de stack niet soeverein.

Residency

Waar staat de data fysiek opgeslagen?

Niet "in de cloud": welk datacenter, in welk land, onder welke jurisdictie.

Subprocessoren

Wie zit er nog meer in uw datapad?

Iedere leverancier die data raakt: de CDN, de e-mailrelay, de error-tracker, de analytics-pipeline.

Rechtsmacht

Wiens wetten kunnen openbaarmaking afdwingen?

Een provider met een Amerikaans hoofdkantoor valt onder FISA 702 en de CLOUD Act, ook als de bits in Frankfurt staan.

Sleutelbeheer

Wie heeft daadwerkelijk de encryptiesleutels?

Als de cloudprovider zowel de data als de sleutels beheert, is die data voor hen leesbaar, ongeacht welke verwerkersovereenkomst er ligt.

Voldoet niet AWS · Azure · GCP · EU-regio

Faalt op rechtsmacht en sleutelbeheer.

EU-bits, Amerikaanse moedermaatschappij, US-subprocessoren in het standaardpad, sleutels beheerd door provider.

Voldoet Binadit managed stack

Slaagt op alle vier.

EU-gehost op EU-hoofdkantoor infrastructuur. Nul US-subprocessoren in het standaardpad. Klant- of EU-KMS-sleutels. Bij naam vermeld in uw Artikel 28 DPA.

Waarom teams weggaan Microsoft Azure

Azure exits typically come from one of three triggers: a public-sector tender that explicitly excludes US-jurisdiction processors, a healthcare or financial services audit that flagged Microsoft 365 + Azure as a single concentration risk under DORA, or a CISO who calculated that the licence true-up costs and "free" Azure credits actually translate to vendor lock-in worth six figures. The Azure ecosystem has tighter coupling than AWS - Active Directory, Office 365, Defender, Sentinel are typically all in the mix - which makes the migration more invasive than its AWS equivalent. It is still doable; we have done it.

Microsoft Azure diensten en hun EU-only equivalenten

Een migratie is niet "vervang één doos door een andere". De mapping hieronder is wat we draaien voor klanten die weggaan bij Microsoft Azure op grond van Schrems II: volledige EU-jurisdictie, geen Amerikaans moederbedrijf in het datapad.

Azure Virtual Machines

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. KVM virtual machines op Debian of Ubuntu, geprovisioned met Terraform en geconfigureerd met Ansible.
Engineering-notitie
IaaS-migratie is eenvoudig; het hoofdstuk over Windows-licenties vergt meer aandacht (BYOL of overstappen naar Linux waar mogelijk).

Azure Blob Storage

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. MinIO of Ceph RGW, S3-compatible.
Engineering-notitie
S3-compatibele EU-storage is het migratiedoel; SDK-wijzigingen zijn minimaal.

Azure SQL Database

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. PostgreSQL of MySQL met Patroni voor failover en pgBackRest voor point-in-time recovery.
Engineering-notitie
Schemaportering vanuit Azure SQL (T-SQL-variant) is de langste afzonderlijke taak; tools zoals AWS SCT of pgloader helpen hierbij. Vaak een goed moment om ORM-keuzes te herzien.

Azure Front Door / CDN

Wat wij in plaats daarvan draaien
Wij implementeren en beheren een EU CDN voor u: Bunny.net of KeyCDN, met Nginx- en Varnish-caching bij uw origin.
Engineering-notitie
Een CDN is een van de weinige lagen die we niet zelf draaien. Wij kiezen de EU-provider, configureren cache headers, purge-strategie en origin shielding, en beheren het als onderdeel van de managed service.

Azure DNS

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. PowerDNS of Knot, authoritative, DNSSEC signed.
Engineering-notitie
Zones worden geëxporteerd en geïmporteerd als standaard zone files, dus dit is meestal het minst gebeurtenisvolle onderdeel van een migratie. Verlaag de TTL's een week van tevoren.

AKS (managed Kubernetes)

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Kubernetes op Debian of Talos, met Cilium networking en cert-manager voor certificaten.
Engineering-notitie
Helm charts en YAML zijn probleemloos overdraagbaar; Azure-specifieke addons (Application Gateway Ingress, Azure CNI) moeten worden vervangen door standaardequivalenten.

Azure Functions

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Knative of OpenFaaS op uw Kubernetes cluster.
Engineering-notitie
De meeste Azure Functions-workloads passen op een klein EU Kubernetes-cluster dat Knative draait.

Azure Active Directory / Entra ID

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Keycloak of Authentik als identity provider, met OIDC en SAML.
Engineering-notitie
De moeilijkste migratie op zich. Plan een parallelle draaiperiode van 3 maanden. SSO-integraties over SaaS-diensten heen moeten opnieuw worden gemapt.

Azure Service Bus / Event Grid

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. RabbitMQ, NATS, of Redis Streams, afhankelijk van de gewenste delivery guarantees.
Engineering-notitie
Managed queueing-opties in de EU-soevereine ruimte zijn beperkt; self-managed is standaard.

Azure Monitor / Application Insights

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Prometheus, Grafana, Loki en Tempo, gekoppeld met OpenTelemetry.
Engineering-notitie
OpenTelemetry-instrumentatie maakt de omwisseling mechanisch voor applicatiecode.

Azure Cosmos DB

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. MongoDB replica sets, of PostgreSQL met JSONB waar het documentmodel dunner is dan het lijkt.
Engineering-notitie
Er is geen 1:1-vervanging voor wereldwijde multi-region active-active; als jouw workload dat patroon echt nodig heeft, is het gesprek anders.

Defender / Sentinel (security)

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Coraza of ModSecurity met de OWASP Core Rule Set, plus CrowdSec voor gedragsmatige blokkering.
Engineering-notitie
CrowdSec heeft zijn hoofdkantoor in Frankrijk en wordt steeds competitiever in de SIEM/IDS-markt.

Key Vault

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. HashiCorp Vault of Infisical, self-hosted, met automatische lease rotation.
Engineering-notitie
Vault is het soevereine antwoord op productieniveau; wij beheren het voor klanten.

Microsoft 365 (email, Teams, OneDrive)

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Postfix met DKIM, SPF en DMARC, en Rspamd voor filtering.
Engineering-notitie
Vaak het lastigere politieke gesprek dan de infrastructuurmigratie zelf. Wordt vaak op M365 gehouden met gedocumenteerde blootstelling in plaats van gemigreerd.

Hoe we migreren af van Microsoft Azure

Een typische mid-market migratie loopt in drie fasen. De getallen hieronder gaan uit van een team van 6-10 engineers en een gemiddeld complexe applicatie-stack.

  1. Weeks 1-3

    Audit & ID-mapping

    Inventory Azure services, Entra ID dependencies, SSO integrations and licensing. The identity layer is the longest tail. Output: phased plan with the SSO migration scoped separately.

  2. Weeks 3-6

    Edge, monitoring, soft dependencies

    Replace Front Door, Azure DNS, App Insights and Blob Storage. Pre-stage EU compute and replicate database. Move CI/CD off Azure DevOps if applicable.

  3. Weeks 6-18

    Compute, DB, identity cutover

    AKS workloads to managed EU K8s. SQL Database to PostgreSQL with logical replication for live cutover. Identity migration with parallel-run; cut SSO over per application.

5-year TCO on Azure exits we have run: typically 25-45% cheaper, with the largest savings coming from licence true-up avoidance and bandwidth/egress. Bear in mind: if your team uses Microsoft 365 and is staying on it, the identity-layer migration only partially decouples - that decision belongs at board level.

Does Microsoft Cloud for Sovereignty solve the Schrems II problem?
It improves the documentation story but does not change the underlying jurisdiction: Microsoft Corporation remains the parent. For workloads where the analysis turns on parent-jurisdiction (i.e. most regulated workloads after Schrems II), it is not sufficient on its own.
What about Bleu?
Licensed sovereign offerings, where an EU entity operates US technology under licence, are pseudo-sovereign - operated by EU-headquartered entities under licence from a US technology partner. They can satisfy specific regulatory requirements (notably the French SecNumCloud certification for Bleu) but inherit a stack they cannot independently maintain. For most buyers, a clean EU-native stack is the architecturally simpler answer.
Can we leave Azure but keep Microsoft 365?
Yes, and many of our clients run that hybrid. The trade-off is that personal data flowing through M365 (email content, OneDrive files, Teams chat) remains under Microsoft processing. Document it in your DPA, apply supplementary measures (encryption at rest with EU-held keys for sensitive folders), and keep customer-data infrastructure on the sovereign stack.
How does this affect our Microsoft Enterprise Agreement?
Existing EAs typically have annual or multi-year terms; the migration target is to stop the next renewal or right-size it, not to break the current contract. Your account manager will offer concessions when they hear "we are evaluating sovereign alternatives." Use that.
Is Active Directory replaceable in practice?
Replaceable in stages. Keycloak handles OIDC/SAML/SCIM well; for Windows-domain authentication on physical desktops, Samba 4 with FreeIPA is the established open-source path. The transition typically runs alongside a "modern workplace" simplification - fewer per-app SSOs, more standard OIDC.
How long does an Azure exit take?
For a mid-size workload (50-200 VMs, 1-2 SQL DBs, AKS, Entra ID): 16-24 weeks elapsed time. With a managed-infrastructure partner driving the choreography: 10-16 weeks. The identity layer is the schedule risk, not the compute.

Plan je exit van Microsoft Azure.

Gesprek van 30 minuten. We mappen je stack tegen EU-only alternatieven, schatten de migratie-inspanning en zeggen je of het de juiste keuze is.