Data Sovereignty and Digital Resilience in the Microsoft 365 Environment
Replace, supplement, or strengthen?
Data sovereignty in the M365 environment is not an either/or situation. The most resilient strategy combines a hardened M365 configuration, sovereign data spaces, targeted open-source components, and—where necessary—European solutions with strong exit and control rights.
Background: Why This Question Is So Relevant Right Now
The discussion surrounding Microsoft 365 (M365) is often framed in binary terms: either the public cloud or a complete replacement with open source. However, sustainable data sovereignty depends not on individual products, but on controllable data flows, managed dependencies, assessed risks, and realistic exit options. Digital resilience refers to the ability to remain capable of acting even in crisis situations—regardless of individual vendors or platforms.
This blog post focuses specifically on the workplace: by "workplace," we mean email, Office, collaboration, file storage, identity, end devices, and supporting security features. While some of these principles can certainly be applied, ERP, OT, and line-of-business systems follow their own rules. What is always crucial are strategies based on protection needs, functional requirements, resilience, and operational capability—not ideology. This makes the sovereignty debate part of corporate strategy: It determines whether digital processes can continue to function and scale resiliently in the face of regulatory changes, geopolitical pressure, or outages.
How secure is Microsoft 365 today?
Microsoft 365 has become the operational foundation for communication, documents, meetings, and identities in many companies and government agencies. Organizations that use M365 entrust key aspects of the workplace to a global cloud provider: identities in Entra ID, documents in SharePoint and OneDrive, communication in Exchange and Teams, and security and compliance features in Purview and Defender. This brings scalability, integration, and innovation, but also creates dependencies on the provider’s operating model, licensing policies, roadmap, and support organization.
Microsoft has taken an important step with the EU Data Boundary. For relevant Enterprise Online Services, Microsoft commits to storing and processing customer data and personal data within the EU/EFTA. Data is stored there at rest. Data residency is thus improved, but the EU Data Boundary is not an absolute “EU-only” protective shield. Microsoft continues to document transfers or access outside the EU Data Boundary, such as remote access by authorized employees, customer-initiated transfers, support data, global security operations, limited Entra directory data, network transit, and optional features and integrations.
The technical implication is clear: M365 can be operated in a more privacy-friendly and controlled manner than an unconfigured standard environment. However, the public cloud does not provide complete self-sufficiency or independence from non-European legal and operational structures. Anyone who processes data with high protection requirements, critical processes, or sensitive research, healthcare, or customer data must also assess risks in the event of a crisis.
In addition to strengthening existing Microsoft 365 environments, independent alternatives and operating models are therefore also gaining importance. These include open-source workplaces, sovereign cloud offerings such as Delos Cloud, as well as alternative workplace concepts such as Workspace by STACKIT.
What's the best way to configure M365?
The greatest short-term leverage lies not in migration, but in consistently strengthening tenant and governance controls. The challenge begins with an assessment: Which data classes are being processed? Which roles access which information? Which third-party apps, connectors, and external shares are active? Which diagnostic data and support processes are relevant? Without transparency, measures remain piecemeal.
Based on this assessment, the specific hardening measures focus on three areas: identity, data, and governance.
Securing Identities
The foundation is the protection of accounts and access: multi-factor authentication, conditional access, secured administrative accounts, break-glass accounts, privileged identity management, blocking of legacy authentication, restrictive app consent management, auditing, and traceable logging. The goal is to consistently secure identities, which are a common target for attacks.
Protect and Encrypt Data
For information, consider sensitivity labels, data loss prevention (DLP), retention policies, eDiscovery and audit concepts, encryption options, Customer Lockbox, and—for particularly sensitive scenarios—double-key encryption. This ensures that it remains possible to control who accesses sensitive content and under what conditions.
Establishing Governance and Auditing
Equally relevant are Teams Federation, guest access, anonymous calendar sharing, external sharing links, third-party apps, and data outflows via the Power Platform, Graph integrations, or browser add-ins. Only end-to-end logging makes sovereignty measures verifiable.
From an organizational standpoint, a checklist is not enough. What is needed are documented risk assessments, data protection impact assessments, transfer impact assessments, a process for developing and evaluating new M365 features, and clear lines of responsibility between data protection, IT security, business units, and operations. The result should be a roadmap: Which protective measures will be implemented immediately, which features will remain restricted, which changes are acceptable to users, and which data categories do not belong in Microsoft 365? The BSI Criteria Catalog C5, which is explicitly intended for cloud customers to assist with their own risk management.
This makes Microsoft 365 more controllable. These measures optimize the Microsoft platform; they do not change the platform dependency. Anyone who views data sovereignty as the maximum freedom of action must also consider the ability to exit, data portability, and alternatives.
Can open source replace Microsoft 365?
One common misconception is: “We’ll replace M365 with a single open-source solution.” There is no such single solution. An M365 replacement is a stack comprising file storage, Office applications, chat, video, email, calendar, identity management, project management, knowledge management, device management, security monitoring, and operations. Open source is strong in some areas but less so in others.
Open source is particularly strong in collaborative data management and web-based office solutions. Nextcloud, ownCloud, and Seafile can partially replace or supplement SharePoint and OneDrive use cases. Collabora Online and ONLYOFFICE handle documents, spreadsheets, and presentations. Mattermost, Rocket.Chat, Matrix/Element, Nextcloud Talk, Jitsi, and OpenTalk cover chat and video. OpenProject, XWiki, Joplin, and similar tools support tasks, projects, and knowledge management. With openDesk , there is also a curated open-source workplace solution featuring Nextcloud, Collabora, Element/Matrix, Open-Xchange, OpenProject, XWiki, and Univention-Nubus, which is specifically tailored for public administration. When it comes to data sovereignty, the key factors are where these components are hosted and who retains control over their operation and the data.
Open source is a solid choice for identity and access management. Keycloak is well-established for SSO, OIDC (OpenID Connect), and SAML (Security Assertion Markup Language). Univention UCS addresses infrastructure and identity scenarios closely aligned with Microsoft AD. midPoint offers robust identity governance capabilities. These solutions can help promote sovereignty but require architectural and operational expertise. They do not automatically replace the deep integration of Entra ID with Windows, Intune, Conditional Access, Defender, and enterprise SaaS applications.
Open source is at a disadvantage where Microsoft provides a highly integrated platform: Unified Endpoint Management, Mobile Device Management, EDR/XDR (Endpoint or Extended Detection and Response), global threat intelligence-driven security monitoring, data governance on the scale of Purview, low-code workflows similar to Power Automate, or complex Office compatibility with macros, templates, and business process integrations. opsi or WAPT can handle software distribution and client management, but they do not fully replace Intune. Open-source MDM solutions are often platform-specific, newer, or more limited in functionality. This is precisely where the practical challenges of a complete switch lie.
Supplementing Rather Than Completely Replacing: The Faster Path to Sovereignty
A complete transition isn't the only option. For many organizations, a complementary strategy is faster and carries less risk. M365 remains in place for standard collaboration and general productivity, while data requiring special protection is processed on a sovereign platform—such as a self-hosted or European Nextcloud environment with Collabora/ONLYOFFICE alongside SharePoint Online.
The increase in control is focused on the data areas requiring the highest level of protection, without immediately having to overhaul the entire workplace. This reduces migration risk, training costs, and loss of functionality. At the same time, it provides an exit and fallback option for critical data, even during a crisis. To ensure this model does not lead to shadow IT, it requires data classification, labels, and DLP rules; clear responsibilities for access permissions, backup, retention, deletion, and eDiscovery; and transparent user guidance.
Can other cloud services replace M365?
Other cloud platforms cannot automatically replace M365—at first, they merely shift the operating model. There are three relevant options.
Sovereign cloud models based on well-known hyperscaler technology
The Delos Cloud is the most prominent German example of this. It is aimed at public sector clients and public institutions in Germany. The approach combines Microsoft technology—in particular Azure and Office 365-related services—with an operational model that ensures technical, operational, and legal autonomy: data storage in Germany, physical separation, operation by a German legal entity, security-cleared personnel in Germany, and oversight in accordance with BSI requirements. This is an attractive option for organizations that need M365 functionality but have higher requirements for confidentiality, national data storage, and regulatory oversight. Delos is not a general offering for every company, nor is it a way to move away from Microsoft technology; rather, it is a sovereign deployment model for authorized user groups.
Alternative workplace suites based on a European infrastructure model
Workspace by STACKIT, for example, combines Google Workspace with STACKIT’s robust cloud infrastructure and is designed for organizations that want to remain productive, reduce their reliance on Microsoft, and strengthen European data control. This option may be of interest to regulated industries, but it is not a purely European software stack. The application layer and product logic continue to come from a global provider ecosystem. Factors to evaluate include data flows, the support model, integrations, AI capabilities, contractual terms, and acceptance of a change in work practices.
Operating an open-source or on-premises Workplace stack on a European cloud, a private cloud, or your own infrastructure.
This model offers maximum design flexibility but requires operational readiness. Platform operations, Kubernetes or traditional servers, IAM, patch management, monitoring, backup, disaster recovery, vulnerability management, tenant isolation, and support must be handled professionally. For an MSP, this can result in a strong service offering. For an in-house IT department lacking the necessary resources, it can become overwhelming.
Multi-cloud diversification can increase resilience and digital resilience when it is thoughtfully designed: clear data zones, a unified identity model, centralized security governance, documented exit scenarios, and tested recovery processes. Especially during a crisis, what matters is not the number of clouds, but whether processes can continue, data can be restored, and decisions can be made independently. Uncontrolled multi-cloud increases costs, complexity, and the attack surface.
Experience shows that data sovereignty is rarely achieved by completely replacing a platform. It is often achieved through a combination of hardened Microsoft 365 environments, sovereign data spaces, open standards, suitable open-source components, and clearly defined exit strategies.
Data Sovereignty in Practice: Three Typical Scenarios
Hardening Microsoft 365
Suitable for organizations that want to continue using Microsoft 365 to its fullest extent. The focus is on security, governance, compliance, and controlled data flows.
Tailored Add-ons for Microsoft 365
Suitable for companies and government agencies with heightened security requirements. Highly sensitive data is processed on sovereign platforms, while M365 remains in place for standard collaboration.
Replace Microsoft 365 Workplace in stages
Suitable for organizations with stringent regulatory requirements or a strategic desire for greater independence. The transition typically takes place gradually over several years and requires additional operational and change management expertise.
Recommendation: Define Your Vision Before Choosing a Tool
The decision should begin with five questions:
- Which data and processes require what level of protection? Not every file requires the same level of sovereignty.
- Which dependencies are critical: providers, identity, file formats, automation, business processes, support, expertise, or cloud infrastructure?
- What are the minimum requirements for security and operations: SLA, patch schedules, logging, SIEM integration, backup, recovery, auditability, and client isolation?
- What exit options are realistic: data export, open interfaces, documentation, alternative service providers, contract terms, and migration paths?
- Which organization can handle operations: internal IT, MSP, vendor support, OSPO, security team, or change management?
Only then does it make sense to decide whether to harden M365, supplement it with a sovereign data platform, replace it gradually, or redeploy it using a sovereign cloud offering.
Conclusion: Sovereignty is not an either/or issue
The correct answer is rarely, “M365 will remain unchanged”—and just as rarely, “Everything must be open source immediately.” M365 can be configured with greater autonomy, but there remains a strong dependence on the platform. Open source can reduce key dependencies, but it requires a robust stack, professional operations, and realistic expectations regarding feature parity. Commercial European products are not a betrayal of sovereignty. They can be useful where open-source solutions have gaps in MDM, endpoint management, security, support, or compliance. Sovereign clouds such as Delos or Workspace by STACKIT do offer options, but they do not automatically resolve every dependency issue.
The resilient approach is a combined model consisting of a hardened Microsoft 365 environment, secure data rooms for sensitive data, targeted use of open source, and carefully evaluated European components—backed by technical and contractual exit capabilities.
After all, data sovereignty is not a product decision, but rather an architectural and governance discipline and a core building block for the future of digital resilience.
Frequently Asked Questions About Data Sovereignty in the M365 Environment
-
What does data sovereignty mean in Microsoft 365?
Data sovereignty in Microsoft 365 means maintaining permanent control over data flows, access, and dependencies. It is not achieved through a licensing model, but rather through hardening, sovereign data spaces, open standards, and clear exit strategies.
-
Is Microsoft 365 fully sovereign under the EU Data Boundary?
No. The EU Data Boundary improves data residency but is not an absolute "EU-only" protective shield. Microsoft continues to document defined transfers and access outside the EU, such as for support, security operations, and certain directory data.
-
Can open source completely replace Microsoft 365?
No, not with a single solution. Open source is strong in file storage, office applications, and identity management, but has gaps in endpoint management, EDR/XDR, security monitoring, and deep platform integration. A replacement always requires a combined stack.
-
How can you configure Microsoft 365 more effectively?
The fastest way to achieve greater data sovereignty is through tenant and governance hardening. This includes multi-factor authentication, conditional access, sensitivity labels, DLP, auditing, and documented risk and transfer impact assessments.
-
What is the Delos Cloud?
The Delos Cloud is a sovereign cloud service for the public sector in Germany. It combines Microsoft technology with data storage in Germany, physical separation, operation by a German legal entity, and oversight in accordance with BSI requirements.
-
What is the best way to achieve greater data sovereignty?
The most resilient approach is a combined model: define protection requirements, harden M365 in a targeted manner, process sensitive data on sovereign platforms, use open source strategically, and ensure the ability to exit both contractually and technically.
Key references are already linked within the text.
In addition:
- Microsoft Learn: Continuing data transfers outside the EU Data Boundary for specific services
- STACKIT: Workspace by STACKIT
- ZenDiS: openDesk – Product Overview
- OSBA: The Open Source Business Alliance Guidelines
Note: This text provides a technical and organizational overview and does not replace a legal review of specific cases.
Written by
Jörg Kähler can look back on 25 years of experience in Microsoft consulting. As Lead Solution Architect, he has been shaping the further development of Microsoft 365 for over ten years. He is responsible for modern managed workplace services that make working environments future-proof.