Microsoft 365 governance: Beyond Encryption

The authority gap in Microsoft 365 for public sector and defense organizations

Microsoft 365 has become a foundational collaboration platform for governments, defense organizations, and regulated public-sector bodies across Europe. Its security architecture is mature, extensively certified, and continuously improved.

Yet, as adoption deepens into high-sensitivity workloads, a structural question remains insufficiently addressed:

Who has the authority to decide on exceptional access to sensitive data, under which jurisdiction, and with what proof?

This paper explains why this question sits outside the scope of encryption alone, why it is not a failure of Microsoft 365, and why public-sector and defense organizations increasingly need a jurisdiction-bound governance layer to complement existing cloud security controls.

What Microsoft 365 does well, and intentionally so

Microsoft 365 is designed to operate at global scale, across thousands of regulatory environments. Its strengths are well known:

  • encryption at rest and in transit
  • strong identity and access management
  • comprehensive compliance certifications
  • continuous security monitoring and incident response
  • mature operational processes

For most workloads, these capabilities are more than sufficient.

Importantly, Microsoft 365 is not designed to arbitrate conflicts of law between jurisdictions, nor to assume legal responsibility for refusing access requests on behalf of sovereign entities. That boundary is intentional and necessary for a global platform.

Where encryption stops answering the hard questions

Public-sector and defense organizations often rely on key-centric models such as:

  • Bring Your Own Key (BYOK)
  • Hold Your Own Key (HYOK)
  • customer-managed encryption keys

These approaches significantly strengthen cryptographic control and reduce risk.

However, they primarily answer one question:

Who holds the encryption key?

They do not fully answer:

  • Who decides whether access should occur
  • under which legal authority
  • how refusals are enforced
  • how those decisions are proven after the fact

Encryption protects data. Governance determines authority.

The authority gap in regulated and defense contexts

In highly regulated environments — such as national administrations, critical infrastructure operators, or defense organizations — the most sensitive scenarios are rarely “normal access.”

They are exception scenarios:

  • internal investigations
  • emergency access requests
  • cross-border legal pressure
  • intelligence or defense-related inquiries
  • post-incident audits

In these cases, the hardest operational task is not granting access. It is refusing access — and proving that refusal was lawful, deliberate, and enforced.

This is the authority gap:

The absence of a clear, jurisdiction-bound decision layer governing cryptographic access to sensitive data stored in global cloud platforms.

Diagram illustrating Microsoft 365 encryption and security, with authority and jurisdiction over exceptional access shown as out of scope by design for global cloud platforms.
Microsoft 365 provides strong encryption and security by design. Authority and jurisdiction over exceptional access decisions sit above the platform and are intentionally out of scope for global cloud services

Why this is not a Microsoft problem to solve

It is tempting to frame this gap as a platform weakness. It is not.

For a global provider like Microsoft, assuming jurisdiction-specific authority would mean:

  • arbitrating between conflicting national laws
  • taking legal responsibility for sovereign refusals
  • embedding local governance logic into a global service

This would be legally, politically, and commercially untenable.

The absence of jurisdiction-bound authority in Microsoft 365 is therefore a design boundary, not an oversight.

Why public sector and defense organizations feel this gap first

Organizations such as the Swiss Armed Forces or industrial defense actors like Airbus operate under:

  • strict national secrecy obligations
  • defense-specific legal frameworks
  • heightened scrutiny from oversight bodies
  • long-term accountability requirements

For these actors, being able to say “data is encrypted” is not sufficient.

They must also be able to say:

  • who had the authority to approve or refuse access
  • under which jurisdictional framework
  • with which independent controls
  • and with what verifiable evidence
Illustration comparing security and encryption with governance and authority in regulated cloud and public-sector environments.
Encryption protects data. Governance determines who can decide, under which law, and with what accountability. Both are necessary — but they address different responsibilities.

A governance-layer approach

One emerging approach is to introduce a governance layer above cloud security, without altering where applications or data reside.

Conceptually, such a layer would:

  • ensure selected repositories store ciphertext only by default
  • require explicit, jurisdiction-bound authorization for any exceptional access
  • separate execution (cloud operations) from authority (legal governance)
  • treat refusal as a first-class, enforceable outcome
  • generate durable, auditable evidence for regulators and oversight bodies

Crucially, this approach does not replace Microsoft 365. It complements it by handling what global platforms cannot reasonably own: local authority and legal accountability.

From SECURITY to GOVERNABILITY

Public-sector cloud adoption is no longer blocked by encryption or technical security. It is increasingly constrained by governability:

  • the ability to decide under pressure
  • to refuse when required
  • and to demonstrate that those decisions were enforced

As cloud platforms continue to mature, governance — not encryption — becomes the differentiator for high-sensitivity public and defense workloads.

Microsoft 365 remains a powerful and secure foundation for public-sector collaboration.The remaining challenge is not security, but jurisdiction-bound authority over exceptional access.

Addressing this challenge does not require moving data, fragmenting platforms, or weakening cloud ecosystems. It requires acknowledging a clear boundary — and complementing it with governance designed for sovereign responsibility.

Bank secrecy is dead, long live digital sovereignty

For a century, Switzerland embodied trust through banking secrecy. Today, it is no longer silence that protects value, but “proof”.

In the age of global data and extraterritorial cloud, the new wealth is no longer in vaults, but on servers — and the question is no longer “where is my data?”, but “under what law does it obey?”.

A change of era

Since the entry into force of the DORA (Digital Operational Resilience Act) regulation, European financial institutions must demonstrate that they control their digital chain, including when their systems rely on international cloud providers. However, most of these providers, mainly American, are subject to the CLOUD Act, which allows Washington to demand the handover of data, even if stored in Europe.

This contradiction places institutions in an unsolvable dilemma: complying with DORA, the GDPR, and national laws while continuing to use global infrastructures.

Until now, the only solution has been to localize the data, a technically complex, economically burdensome, and legally incomplete model. Because moving data does not move the law: even when hosted locally, it often remains subject to foreign jurisdictions through the operators or tools it uses.

The Swiss idea: no longer moving data, but sovereignty.

This is where the approach developed by JaaS39 comes in, a Swiss technological and legal initiative that reverses the logic by bringing sovereignty to where the data is, rather than moving the data to European or even Swiss datacenters .

In practical terms, JaaS39 installs a fiduciary capsule, a certified software component, within the client’s digital environment (public, private, or hybrid cloud). This capsule creates a zone of Swiss jurisdiction at the very heart of the foreign infrastructure. All sensitive operations (encryption, signature, auditing) are executed under Swiss fiduciary custody, that is, within a neutral legal framework governed by Swiss law.

The data itself doesn’t change by a single byte:

Only the control decision crosses the border, in an encrypted and verifiable manner.

From law to code: sovereignty as a service

This mechanism, called Jurisdiction-as-a-Service (JaaS) , transforms a legal principle—sovereignty—into digital infrastructure. Where hyperscalers promise compliance, Switzerland can now certify it. Each deployed module becomes a digital “micro-consulate” of Swiss neutrality: an autonomous and traceable enclave of law, continuously auditable by regulators.

This approach is now aligned with the latest European standards:

  • DORA RTS 2024 on operational resilience,
  • EUCS Sovereign Cloud 2025 level 3 (“Enhanced”),
  • and FINMA 23/1 on the technological continuity of critical infrastructures.

A structural advantage for regulated institutions

For banks, insurers, fintechs or healthcare providers, the benefit is immediate:

  • no data migration,
  • Verifiable conformity
  • divided governance costs,
  • Automated continuous auditing.

For states and regulators, this approach offers an unprecedented lever: the possibility of verifying sovereignty without encroaching on confidentiality. Every transaction, every signature, every access is recorded under Swiss control, but without Switzerland seeing the data itself.

This is the principle of zero-knowledge compliance: governing without monitoring.

And what about Switzerland?

By exporting this architecture, the Swiss Confederation is not selling a technology, but a method. It becomes the source of reproducible neutrality, a model that other jurisdictions can certify locally while maintaining Swiss traceability. This is a new form of digital diplomacy, where trust is no longer negotiated through treaties, but through verifiable algorithms.

The market to conquer

The European market for verifiable sovereignty is estimated at 3.5 billion Swiss francs by 2028, boosted by DORA, NIS2, and future directives on artificial intelligence. Hyperscalers themselves acknowledge that their “localized” model is no longer sufficient.

What JaaS39 offers is not an alternative, but an indispensable complement: the missing 5% that makes an infrastructure truly sovereign.

Programmable neutrality

In a world where every power wants to repatriate its data, Switzerland can become what the international system has lost: a universal trusted third party.

Swiss neutrality, once institutional, is becoming programmable. Thanks to cryptographic proofs and fiduciary governance, Switzerland can protect the world’s data without possessing it, just as it once protected assets and secrets.

Digital sovereignty as a new asset

Bank secrecy is dead, that’s true, but it is reborn in another form: that of an auditable digital sovereignty, stronger, more legitimate, and more useful to the global economy.

For the first time, sovereignty is not a claim — it’s a capability.

Institutions, regulators, technology partners: Switzerland isn’t waiting for Europe to come to it. It’s bringing compliance, neutrality, and trust to where the data is.

Hello world!

Welcome to WordPress. This is your first post. Edit or delete it, then start writing!