OC3 2026 | Azure confidential computing in the sovereign cloud era with Vikas Bhatia

OC3 2026 | Azure confidential computing in the sovereign cloud era with Vikas Bhatia

Microsoft Azure

0:06 (bright music)- [Vikas] Great.

0:13 Hi everyone.

0:14 I am presenting live from Seattle and I can't see

0:19 the room as it's my first time using this system, so we'll work through it.

0:26 Thank you so much for the time and being here.

0:30 So as was mentioned, rather than what I've done in the past cover

0:34 sort of what we are doing on the product side,

0:38 which I'll still get into, but this time I did want

0:41 to talk about what we are seeing with Azure Confidential Computing,

0:45 especially with all the activity and progress

0:49 happening in the sovereign cloud space.

0:52 So with that, let's get started.

0:57 So first thing I'll cover is what are

0:59 we seeing as part of the sovereignty requirements?

1:01 What do we think about Confidential Computing at Microsoft?

1:04 And then talk a little bit about our roadmap with Azure Confidential Computing.

1:09 So first, let's get started.

1:11 From a sovereignty perspective, we have been in this space for a while and we

1:18 have been working with customers and we have learned a lot,

1:20 and that's what we wanted to share.

1:23 So essentially when it comes to the sovereignty space,

1:25 we are seeing every few days, new regulations emerge,

1:30 shaping how we use AI, how do we manage data,

1:34 how do we secure our digital services?

1:37 In fact, the last time we checked there were over a hundred,

1:40 over a thousand global policy initiatives across 69

1:44 countries and a hundred nations enforcing these privacy laws.

1:48 And this isn't just a technology challenge, it's a trust challenge.

1:54 This is sort of why digital sovereignty matters.

1:56 It gives organizations and companies and sovereign nations the ability

2:01 to innovate on their own terms while maintaining compliance,

2:05 control and security.

2:08 So before we start off,

2:09 I think it's important to mention what is digital sovereignty.

2:13 At its very core, digital sovereignty is

2:16 the capability to participate in this digital economy,

2:20 securely, independently, and with self-determined controls.

2:25 So we need to be connected

2:27 and work with sort of these international organizations,

2:30 international customers, and international providers.

2:33 And our approach to the digital sovereignty is pretty straightforward.

2:37 Digital sovereignty should be foundational to our cloud end services.

2:41 It's delivered through a well governed combination of technical,

2:45 contractual, and operational controls.

2:47 And because every workload in every organization

2:50 has different levels of sensitivity and criticality,

2:54 sovereign requirements themselves are adaptable to the needs

2:57 of each workload that we see.

3:02 So we have been active in this space for a while over the last 10 odd years.

3:08 So you'll see that over a decade,

3:11 we've made investments in privacy, security, compliance,

3:13 all the way from GDPR to the German

3:17 sovereign cloud to launching the Microsoft Cloud with sovereignty.

3:20 And as was announced by Satya, our CEO back in June,

3:24 Microsoft Sovereign Cloud is the next step in this journey.

3:28 And now I will drain each of these compliance offerings one by one.

3:31 No, but we do have a bunch of compliance offerings

3:35 that are super critical to organizations using workloads in production.

3:41 These sort of capabilities are critical for enterprise workloads.

3:46 So when we now talk about Microsoft Sovereign Cloud,

3:50 we are building on our existing experience

3:52 of delivering sovereign capabilities across our cloud.

3:55 So this spans both the public cloud and the private infrastructure

4:00 so the customers can choose what is the right balance of control,

4:04 compliance, and capability.

4:06 So this solution that we are talking about here is

4:09 designed to enable organizations to have

4:11 comprehensive solutions across sovereign public

4:14 cloud and to cater to specialized needs like what we

4:18 see in the sovereign private cloud and the sovereign partner system.

4:24 So when we talk about the Microsoft Sovereign Cloud,

4:28 it is built to support the full spectrum of these needs,

4:32 whether those are regulatory requirements so that customers

4:36 can have confidence in the data and operations,

4:38 to meet local and national compliance standards,

4:42 or whether there are sovereign data AI

4:44 processing requirements or the no cloud operator access,

4:47 meaning that customers retain authority,

4:50 their data and workloads stay protected with safeguards,

4:54 against unauthorized access even from Microsoft.

4:57 Our data residency plays a big role here.

5:00 And finally, obviously business continuity to ensure

5:03 that mission critical workloads can continue

5:05 securely even in the event of natural or as we are seeing today,

5:11 the geopolitical situations around the world.

5:15 So when we dig into sort of the no cloud operator access, what does that mean?

5:21 What we see is customers want to protect their sensitive data,

5:25 not just from hackers but from themselves or even the cloud provider.

5:30 So they can do this through a layered approach.

5:33 Obviously, you know, in the industry,

5:36 it is encrypting data and rest and in transit is a standard already.

5:42 And then with Confidential Computing,

5:44 customers can keep the data encrypted from outsiders while it's being processed.

5:49 With Confidential Computing available and customer

5:52 managed keys themselves play a big

5:54 role in this, especially when our customers use our managed HSM offering,

5:59 which is itself a confidential key management solution that we built.

6:03 The data remains private, governed and fully under customer control,

6:08 even in the most sensitive and regulated environments.

6:12 So when we talk about digital sovereignty,

6:15 this can mean different things to different people with needs that vary,

6:20 you know, even between workloads, it's not a one size fit all

6:23 and it's splits into operational controls and data controls.

6:28 So in operational controls as an example, you know,

6:31 we have advanced data residency needs for Microsoft 365.

6:35 And for data controls,

6:36 we have a bunch of offerings around Azure Key Vault Premium,

6:39 Azure Key Vault Managed HSM,

6:41 sovereign landing zones and of course Azure Confidential Computing.

6:47 So before I start digging into the Confidential Computing side,

6:51 one of the most important elements that we hear from customers is keys,

6:56 customer managed keys, and specifically their requirements from the Azure

7:00 Key Vault Managed HSM offering that we have where customer's keys are secured

7:04 and highly available in these single tenant HSMs,

7:08 where strict sovereignty controls are enforced via confidential enclaves.

7:14 So with Managed HSM, we have centralized key management capabilities,

7:19 which manage keys across the organization and integrates

7:23 with the various Microsoft services that we have,

7:26 ranging from Microsoft 365, to Azure Storage to Cosmos DB.

7:31 And all of this is integrated with Azure

7:34 policy to allow automated key management at scale.

7:37 This is sort of what we are hearing from our customers.

7:41 So as we dig in deeper into the stack,

7:44 we have put sovereign controls at every layer of the stack,

7:48 whether that's our data center, DCSCM secure control module,

7:53 the integrated HSM of the on node FIPS 140-3 compliant,

8:01 HSM cache that we recently announced that will ship

8:05 with every node that we will have, of course,

8:08 the work that we've done with Azure Boost that we are extending more,

8:12 and I'll talk about it more about how Confidentiality integrates with it.

8:16 And of course, Confidential Computing becomes a key part of the solution

8:19 here for how we use hardware-based DEs to protect these sovereign workloads.

8:25 So when we have been working with the industry,

8:28 here are the four sort of your key partners that we have,

8:32 ranging from G42 in UAE, Korea Telecom in South Korea,

8:36 Leonardo and Proximus as well in the EU that we've been working for a while.

8:42 And based on this I think what we have decided to do here is share what are

8:47 the sort of sovereign workload types that we are

8:51 seeing actively employed and deployed in Azure Confidential Computing.

8:55 And there is a range, right?

8:57 Eventually all workloads will operate this way,

9:00 but initially what we see is, you know, high sensitivity business applications,

9:05 whether there was a line of business

9:07 applications requiring strict data sovereignty, operator isolation.

9:13 This includes internally developed apps and apps that are, you know,

9:18 either third party software deployed via lift and shift capabilities.

9:23 We've also seen core infrastructure components,

9:27 what we call the foundation layer,

9:29 whether those are domain controllers running inside

9:32 CDMs or identity services are running inside, you know, Confidential Computing.

9:37 These are the foundational pieces that are critical to the organization

9:41 and we see them starting to run in Confidential Computing.

9:44 The next layer that we expect to see

9:47 a lot more on is the data and analytics workloads.

9:50 Whether those are large scale analytics running on Kubernetes

9:53 work nodes or something that is more sort

9:57 of a compute intensive pipeline requiring high I/O ops

10:02 between sort of the components running in the compute

10:06 stack and further down the line we see

10:08 a lot of interest in sort of these confidential

10:11 databases and stateful services where we start seeing

10:17 the next layer of maturity in these workloads where, as I mentioned earlier,

10:22 the line of business applications start becoming

10:25 real with real sort of workloads being deployed.

10:29 I won't go through these two videos, but I'll link them here.

10:33 These are two sort of our closest partners with G42 and Korea Telecom,

10:38 and we've learned a lot with them.

10:39 So what I showed you on the previous slide was some of the learnings

10:42 after working not just with them but also many other customers in this space.

10:47 Let me go ahead here.

10:49 So with that, I'm going to now shift into, okay,

10:53 this is what I just showed you was what we

10:56 are seeing and learning from sovereign workloads around the world, right?

11:00 Whether that's in EU, whether that's in the Middle East,

11:03 whether that's an APAC or even in the United States,

11:07 we are seeing similar sort of requirements, similar sort of capabilities.

11:13 And one of the key important elements that comes through is mission

11:16 critical software that needs to run

11:19 with mission critical workload resiliency requirements.

11:22 So when we look at sort of Confidential Computing at Microsoft,

11:25 we've done a bunch of effort with our Secure Futures Initiative.

11:30 This is something that we've been on for a couple of years.

11:34 It's basically a process of continuous improvement,

11:37 whether that's protecting identities and secrets,

11:39 isolating our production systems, our networks or engineering systems.

11:45 We do a ton of work on monitoring and detecting threats.

11:49 And this is sort of the goal.

11:51 It's to get secure by design,

11:53 secure by default, ensure we have secure operations.

11:57 And one of the key sort of capabilities here

12:00 is when we talk about protecting our identities and secrets,

12:04 the first element in this is running on Confidential Computing.

12:08 So we announced this a while back now, well, in 2024, but at the end of 2025,

12:17 we have 100% migrated our identity stack

12:21 onto Confidential HSM that I talked about before,

12:24 and the Confidential Computing stack.

12:26 So this helps our customers get more assurance that the identity

12:32 stack that they're using is secure and protected from the cloud operator.

12:39 Now this is just the identity stack.

12:42 So when we think beyond the identity stack, we have, oh, sorry about that.

12:49 We have a concept of the Azure TCB,

12:51 which is what is in the Azure Trusted Computing Base.

12:55 So in the Azure Trusted Computing Base,

12:58 the first element that comes through is we have

13:00 our data center and hardware capabilities that we deploy,

13:04 you know, in our data centers.

13:06 And on top of that we run our foundational PCB elements,

13:10 the foundational building based, this is our computer hosting, our deployments,

13:14 our operational management, our private key infrastructure,

13:18 SQL management, inventory control,

13:19 pretty much everything that is foundational to running the Azure Cloud.

13:24 So we are, you know, slowly moving and in many cases move quite

13:29 a lot of them over to Confidential Computing.

13:33 The current default is Trusted Launch,

13:36 the future default will be Confidential VM.

13:38 And then as we know, containers provide a much tighter TCB than a VM.

13:44 The future standard would be confidential containers,

13:47 given that you can attest every layer of the container stack.

13:50 And on top of that, it's sort of where we build our VMs,

13:52 containers, our products and services,

13:55 our customer workloads around on top of it.

13:57 So we see sort of this progression happening gradually over time as the stack

14:02 matures and we see more

14:04 of these workloads running real mission critical software.

14:10 So now, let's shift gears.

14:12 I talked about, you know, what we are seeing in the sovereignty space,

14:15 how we are looking at Confidential Computing inside Microsoft.

14:19 Now let's talk about, okay, what do we see ahead, you know,

14:22 what's going on right now in the Confidential Computing space from Microsoft?

14:26 So first we have the AMD V6 Confidential VMs

14:31 on AMD SEV-SNP that we have GAed in 19 public regions.

14:37 I think it's 40 availability zones.

14:42 And we also GAed them in the Azure government regions.

14:45 And over time, you know, we will be GAing in additional regions.

14:50 The regions are listed down below.

14:53 And in terms of feature capabilities, we have,

14:56 you know, 25% performance boost over the last generation.

15:00 We have suppose for, you know,

15:02 key capabilities such as online key rotation, backup restore,

15:08 migrate, all of those fundamental capabilities

15:11 that make a Confidential VM a great VM.

15:13 All of those capabilities are also coming online.

15:15 Also things like Kubernetes support is already there for a while,

15:19 but this sort of stack is running our identity stack that I mentioned earlier.

15:25 A lot of our stack, you know, our foundational TCB runs on this as well as many

15:30 of the customer workloads that I talked about in the sovereign space,

15:33 not just the sovereign space, but overall regulated environment that we see.

15:38 And very recently, I would say as recently as a couple of weeks ago,

15:44 I suppose we announced the Intel TDX V6,

15:47 Confidential VM GA, general availability.

15:50 This one has OpenHCL convert, which is open source now to improve

15:56 the transparency that we can provide to customers.

15:59 And right now, at GA, we have the accelerator and VME local storage,

16:06 the key guard support up to 128 VCPUs and 512 gig memories.

16:12 But even post GA, we will be releasing additional features addressing,

16:18 you know, performance gaps in the offering.

16:23 And then regional availability will also increase sort of over time.

16:28 So we started Gaing in a couple of regions and you know,

16:32 more will come online over time

16:34 as we run through our secure deployment processes.

16:40 So the next thing I did want to talk about is sort

16:42 of the innovative work that we are doing in our hardware offload capabilities.

16:49 So some of you may know about Azure Boost,

16:52 it's about infrastructure acceleration.

16:55 So typically on the left side you'll see traditional infrastructure where,

16:59 you know, there's a hardware and then you have the host operating system,

17:03 you have KBM or your Windows hypervisor running the stack,

17:07 which on top of it runs the customer workloads.

17:11 So when you shift the right side is when you move to an offloaded infrastructure

17:16 environment where Azure Boost is now doing

17:20 the accelerated offload that it's running the agents,

17:23 it's running the host capabilities, you know, storage, networking, et cetera.

17:26 And what you have is that the node is now available,

17:31 100% available for the customer workloads.

17:34 So you have the VMs and containers running in the node and there's an I/O layer.

17:39 And in addition to sort of the hardware acceleration,

17:42 there is a security and resource boundary,

17:45 isolation boundary that gets created because you have capabilities like Boost.

17:50 So with Azure Boost, you know, we have a bunch of sort

17:53 of capabilities around 20 gigabits per second throughput,

17:58 one million disk I/O ops, 400 gigs networking.

18:01 But the thing that I want to get your focus

18:05 on is the work that we announced as part of ABCD,

18:09 which is Azure Boost Confidential Device,

18:11 which is using the T risk standard for encrypted I/O.

18:15 This is something that we announced recently and we are actively working on it,

18:18 but this will now start eliminating the gaps between confidential and non

18:24 confidential environments because this is sort of what customers are asking for.

18:28 They want a no asterisk Confidential Computing environment.

18:33 So when you compare it side by side without confidential device offload,

18:37 as we know for a long time, we've had to do bounce buffering,

18:42 which adds additional CPU cycles to the customer workloads, which is not ideal.

18:48 So the customer has to pay extra for getting

18:51 the sort of I/O that they need, right?

18:54 But with ABCD or with device offload, you now have say a confidential virtual

19:01 machine directly connected to the confidential device.

19:06 The Boost confidential device through an ID encrypted PCIE link direct chain.

19:12 So, you know, the benefit of it obviously is it enables confidential offloads,

19:18 but it reduces or decreases the CPU's usage,

19:23 enabling these accelerated data transfers between

19:26 the CVMs and directly to the devices.

19:29 This will become critical for high I/O throughput need workloads,

19:36 for AI bound workloads, you know, running large LLMs.

19:43 But with this capability,

19:44 we start removing sort of the final asterisk around making

19:48 Confidential Computing essentially fully capable to its non CC honor products.

19:55 This is not a comprehensive list, but you know,

19:58 you may have seen this list before,

20:00 but the way we think about our capabilities is we first sort

20:04 of been working the intra layer with our partners and, you know,

20:08 AMD, Intel, Nvidia, et cetera to start

20:11 bringing in the capabilities and the silicon.

20:15 We build virtual machines and containers on top of it,

20:19 integrating with Kubernetes or serverless and ACI using

20:22 a virtual node if there's a hook needed with Kubernetes.

20:26 But those are the foundational elements.

20:29 And on top of that, we start adding sort of the services.

20:32 And this is not a comprehensive list as I mentioned,

20:34 but this is around things like,

20:36 you know, we have Azure badge capabilities available via Azure Data Explorer.

20:41 One of our most popular first party services

20:45 is Confidential Azure Virtual Desktop as an example.

20:49 And we've done sort of work on the confidential inferencing with Azure OpenAI,

20:54 I already mentioned the identity services.

20:56 And there's a bunch of sort of services that, you know,

21:00 inside Microsoft we call it, if you're in field and sales,

21:05 you say, you know, drink your own champagne or if you're in engineering,

21:09 we say eat, you know, eat your own dog food.

21:11 So we have been spending a bunch of effort

21:14 on improving the security story of our internal first party workloads,

21:19 getting them mission critical,

21:20 getting them ready for sort of this, you know, higher secure environment.

21:25 So with that, let me kind of get to the closing elements.

21:31 So when we talk about Confidential cloud,

21:33 what we mean is, you know, basically around these four vectors,

21:38 one, data's fully in control the customer,

21:41 whether that's at rest, in transit or in use.

21:44 The cloud provider, which in this case is Azure

21:47 or even the customer themselves are outside the trusted computing base.

21:52 The code running in the cloud is protected.

21:57 It's not just trust, it's also verified by the customer.

22:01 And activity history is immutable and auditable.

22:05 So thank you so much for your time.

22:08 Apologies for the earlier technical difficulties.

22:13 (bright music)

Study with Looplines Download Captions Watch on YouTube