Under my Airbus piece a fortnight ago, a reader asked a really good question: what identity solution have they deployed? Moving your systems to a European cloud is quite something, he pointed out, but if reaching them still runs through an American identity provider, you may have moved the crown jewels and left the keys with the old landlord. Airbus has never said publicly what it did about identity. I have been turning the question over since, because I suspect it is the most important one in the whole sovereignty debate, and the least asked.
The Gate, Not the Rooms
Start with what an identity provider actually is, because "login system" undersells it badly. Your IdP is the one system every other system trusts. It decides who is who, which permissions travel with them, how long a session lives, and whether the multi-factor challenge is satisfied. Every application you have federated — the ERP, the document store, the AI assistant with its enthusiastic reach — accepts its word without further question. That is the design. Single sign-on concentrates authentication precisely so you only have to defend one gate.
Concentration cuts both ways, though. If you wanted to reach everything an organisation holds, you would not go system by system. You would go to the gate.
Whose Law Reaches the Gate
Now apply the test this series keeps applying. The enterprise identity market belongs overwhelmingly to Microsoft Entra and Okta, both American companies, both within reach of American law wherever their infrastructure sits. An EU data-residency cell changes the geography, not the jurisdiction; the operator is the operator.
I will not speculate about what US authorities could compel an identity provider to do — the public record does not support the dramatic versions, and the argument does not need them. The dependency alone is the point: the system that decides who can reach your data answers, ultimately, to someone else's law and someone else's commercial decisions. Price rises, service changes, sanctions, export controls: each arrives at your front gate before it arrives anywhere else.
The Admission in the Documentation
The finding that convinced me this piece needed writing comes from Microsoft's own documentation. Azure Local's disconnected operations — the fully disconnected tier I called the genuine article in the last piece — does not support Entra ID. Microsoft's most sovereign product cannot use Microsoft's own cloud identity service. Identity in the disconnected tier is handed back to you: Active Directory and AD FS, run locally, with your own certificates and your own control plane.
When Redmond builds an environment isolated enough to deserve the word sovereign, the first dependency it removes is its own identity cloud. I can think of no clearer admission, from any vendor, of where the anchor sits.
Europe Built the Passport Office and Rented the Keys
Europe, meanwhile, has been legislating identity with real ambition — just not this identity. eIDAS 2 obliges every member state to give citizens a Digital Identity Wallet by the end of this year, with cross-border recognition and adoption targets stretching to 2030. Citizen identity, the passport in your pocket, is becoming sovereign European infrastructure by law.
Workforce identity, the layer that guards the actual data, has been left entirely to a market America owns. Europe built its own passport office and still rents the office keys.
Three Things To Do About It
So what would I do about it, sitting inside a normal organisation rather than a policy paper? Three things, none of them heroic.
- Score the identity layer in every sovereignty assessment, using the same columns as the workloads: who operates it, whose law reaches them, what happens if it stops. Most assessments I have seen list the IdP as plumbing and move on. It belongs at the top of the register, not in the footnotes.
- Know your alternatives before you need them. European providers exist — cidaas runs under German law, Keycloak is open source and as sovereign as whoever operates it, and unfashionable on-premises AD FS is still quietly holding up some of the most isolated environments in the world, including, it turns out, Microsoft's. You do not have to move to any of them today. You do have to know your route and your cost, because an exit you have never priced is not an option, it is a hope.
- Keep break-glass access that depends on no cloud at all: local accounts, sealed credentials, tested now and then, so that the day your identity provider is unreachable — for any reason from outage to geopolitics — is a bad day rather than the end of the story.
The Thread
The thread through this series keeps being the same one. Residency is geography, sovereignty is jurisdiction, and jurisdiction follows the operator. Identity is where that logic bites hardest, because the IdP is the operator every other operator defers to.
Next in the series, 20 August: what a credible European AI layer would take, in compute, capital and control.
Until then, a question worth carrying into your next architecture review: if your identity provider disappeared behind someone else's law tomorrow, how long before you could open your own front door?