Skip to main content
🇺🇸 Microsoft Corporation US jurisdiction

Microsoft Entra ID

Cloud-based identity and access management service (formerly Azure Active Directory) for SSO, MFA and conditional access

Elevated Risk (Score: 2.45/5)

Hosting & Jurisdiction

Data Residency
🇳🇴 NO 🏳️ EU/EEA
Jurisdiction Exposure
🇺🇸 US
Self-Hosted No

Cloud-only. Norway datacenter available. EU Data Boundary supported. US jurisdiction still applies to identity data.

⚠️ Jurisdiction Risk

This product is subject to foreign jurisdiction (US), which may allow foreign authorities to compel data disclosure.

Key Concerns

  • Subject to US CLOUD Act - identity data particularly sensitive
  • Cloud-only with no self-hosting option
  • Central dependency for Microsoft 365 users
  • Single point of failure for authentication

NDSI Assessment

Norwegian Digital Sovereignty Index v1.0 - Assessed 2025-12-19

Data 2/5

EU Data Boundary available, Norway datacenter

Environment 1/5

Microsoft carbon commitment

Legal 3/5

Subject to CLOUD Act. Identity data highly sensitive.

Local presence 1/5

Norway datacenter, strong partner network

National security 3/5

Identity provider = critical infrastructure. US jurisdiction concerning.

Operational 3/5

Cloud-only, central to Microsoft ecosystem

Security 1/5

Strong security features, Conditional Access, PIM

Strategic 3/5

US company, dominant in enterprise identity

Supply chain 2/5

Part of Azure/Microsoft 365 stack

Technology 2/5

SAML/OIDC standards but proprietary platform

What You Can Do

Enable EU Data Boundary

Configure for EU data storage using Norway datacenter

Effort: Low Impact: Medium
Learn more →

Implement Conditional Access

Use location-based policies and device compliance

Effort: Medium Impact: High

Use Privileged Identity Management

Enable just-in-time admin access

Effort: Medium Impact: High

Alternatives

Technical Details

Open Source No
Data Portability Partial
Self-Hosted No

Sources