系列專欄:從 AWS 視角征服 Azure:AZ-900 30 天通關實戰
難度指數:★★☆☆☆
核心考點:Sovereign Clouds (Azure Government / Azure China 世紀互聯 / Azure Germany), Compliance (Trust Center / Service Trust Portal / Compliance Manager), Data Residency, AWS GovCloud 對照
在 Day 1 和 Day 2 中,我們學習了 Azure 的邏輯管理階層(Management Groups ➔ Subscriptions ➔ Resource Groups)以及全球實體基礎建設(Regions, AZs, Region Pairs)。
在絕大多數的商業應用場景中,商業版 Azure (Azure Commercial / Global Azure) 已經能滿足 99% 企業的需求。但如果你任職的公司接下了美國國防部 (DoD) 的軍工標案,或是要在中國大陸市場上線系統,甚至是需要滿足歐盟極度嚴苛的數據邊界要求時,一般的商業公有雲能直接使用嗎?
答案是:不行!
微軟為此打造了特殊的 Sovereign Clouds(主權雲 / 獨立合規雲) 以及一套嚴密的合規驗證體系。今日 Day 3,我們將深入剖析 Azure 的「特務級」雲端環境,並結合 AZ-900 考古題真題,帶你輕鬆拿下這個必考章節! 本文使用antigravity ide 3.6 flash agent 整理

我們先透過一張完整的對照表,快速釐清 AWS 與 Azure 在主權雲與合規管理上的設計:
| 雲端場景/服務 | AWS 概念 | Azure 對應概念 | AZ-900 關鍵考點與靈魂細節 |
|---|---|---|---|
| 美國政府專用雲 | AWS GovCloud (US)(East & West) | Azure Government(包含 Azure Government DoD) | • 資格嚴格限制:僅限美國聯邦/州/地方政府機構及經過資格認證的美國政府承包商 (U.S. Contractors)。• 實體與網路物理隔離:擁有獨立資料中心與獨立 Portal (portal.azure.us),背景審查人員需為美國公民。 |
| 中國獨立營運雲 | AWS China(由光環新網 / 西雲數據營運) | Azure China(由世紀互聯 21Vianet 獨家營運) | • 法遵實體隔離:微軟因應中國《網絡安全法》,由中國本土持照業者「世紀互聯 (21Vianet)」獨家營運與維護。• 獨立 Endpoint:使用 portal.azure.cn,與 Commercial Global Azure 帳號與網路完全隔離。 |
| 歐洲數據落地雲 | AWS Europe Sovereign Cloud | Azure Germany (歷史經典考題) | • 考題陷阱:只要有德國數據落地與合規需求的任何全球企業/用戶皆可申請使用,非僅限德國公民(Any enterprise requiring data residency in Germany)。 |
| 合規認證公開平台 | AWS Compliance / AWS Services Directory | Azure Trust Center (信任中心) | • 公開網站:免登入!提供微軟 90+ 項全球、區域與產業合規認證(如 ISO 27001, SOC, FedRAMP, GDPR)的總覽與聲明。 |
| 審計報告與合規評估 | AWS Artifact | Service Trust Portal (STP)➔ Compliance Manager | • Service Trust Portal:需登入!下載第三方獨立審計報告(SOC, ISO audit reports)。• Compliance Manager:工作流工具,協助企業追蹤、指派與驗證合規性防護措施與風險評估。 |
┌────────────────────────────────────────────────────────────────────────┐
│ Global Azure (商業版公有雲) │
│ - Endpoint: portal.azure.com │
│ - 涵蓋全球 60+ Regions (East US, East Asia, Japan East, etc.) │
└────────────────────────────────────────────────────────────────────────┘
│
┌────────────────────┴────────────────────┐
│ 物理與邏輯完全隔離 (Physically Separated) │
▼ ▼
┌──────────────────────────────┐ ┌──────────────────────────────┐
│ Azure Government │ │ Azure China (21Vianet 世紀互聯) │
│ - Endpoint: portal.azure.us │ │ - Endpoint: portal.azure.cn │
│ - 客戶資格:美國政府與承包商 │ │ - 營運商:中國本土世紀互聯 │
│ - 滿足 FedRAMP High / DoD │ │ - 滿足中國網絡安全法與數據出境 │
└──────────────────────────────┘ └──────────────────────────────┘
💡 架構師重點筆記(AWS 轉換心法):
- 帳號無法跨雲通用:你在
portal.azure.com申請的商業版 Azure 帳號,無法直接登入portal.azure.us或portal.azure.cn!必須單獨進行專屬審核與開戶。- 合規工具雙雄分工:
- 想看微軟拿了哪些認證 ➔ 查 Trust Center (信任中心)
- 想下載審計報告或評估自己公司是否符合 ISO 27001 ➔ 用 Service Trust Portal (STP) 裡的 Compliance Manager (合規性管理員)
Sovereign Clouds (主權雲 / 獨立雲)
Azure Government (美國政府雲)
Azure China (Azure 世紀互聯)
Azure Trust Center (信任中心)
Service Trust Portal (STP) & Compliance Manager (合規性管理員)
Titan 科技迎來了成立以來最大的業務轉折!今天早上的戰略會議中,CTO 與法務長 (General Counsel) 嚴肅地向你提出了兩大業務需求:
法務長:「架構師,我們剛拿下了美國國防部 (DoD) 的二級供應商合約,同時我們在中國市場的子公司準備推出在地化服務。美國政府要求資料庫與系統必須部署在符合 FedRAMP High 且僅限美國授權人員維運的環境;而中國法務團隊強調,中國使用者的數據絕不能離開中國境內,且必須由中國在地企業營運!」
CTO:「我們能不能直接用目前商業版的 Azure (East US & East Asia) 搞定?還是需要什麼特殊架構?」
身為 Titan 科技的 Chief Cloud Architect,你會提出哪一個方案?
East US 建立美國國防部系統,並在 East Asia (香港) 建立中國系統,因為 Azure 已經具備 ISO 認證。✅ 正解:B
❌ 陷阱分析:
為了確保你能輕鬆拿下 AZ-900 考卷上關於主權雲與合規性的分數,以下精選 3 題真題考古題 進行深度拆解:
【Question】 (選自 AZ-900 考古題真題 Question 69)
Which two types of customers are eligible to use Azure Government to develop a cloud solution? Each correct answer presents a complete solution.
C、D
【Question】 (選自 AZ-900 考古題真題 Question 63)
Review the underlined text. If it makes the statement correct, select "No change is needed". If the statement is incorrect, select the answer choice that makes the statement correct.
Azure Germany can be used by legal residents of Germany only.
D
【Question】 (選自 AZ-900 考古題真題 Question 79 & 82 綜合精選)
What should you use to evaluate and track whether your company's Azure environment meets regulatory requirements and compliance standards, such as ISO 27001 or GDPR?
C
⚠️ 來源說明:本題改寫自 2020 年 gratisexam AZ-900 題庫(Q82),屬歷史題庫層,已與 Microsoft Learn 交叉驗證,考點至今仍然有效。
【Question】
評估底線文字是否正確;若正確選「No change is needed」,若錯誤選出使敘述正確的選項。
From Azure Cloud Shell, you can track your company's regulatory standards and regulations, such as ISO 27001.
(可以從 Azure Cloud Shell 追蹤公司的法規標準,例如 ISO 27001。)
C. Compliance Manager
⚠️ 來源說明:本題改寫自 2020 年 gratisexam AZ-900 題庫(Q59 一帶),屬歷史題庫層,已與 Microsoft Learn 交叉驗證,考點至今仍然有效。
【Question】
Titan 科技的稽核人員想快速瀏覽 Azure 目前已取得哪些合規認證(例如 ISO、SOC、各國法遵),以判斷是否符合其所在地區的法規要求。應該使用哪一項?
A. Trust Center
| 項目 | 內容 |
|---|---|
| 對應課程章節 | 第 2 章 Azure 架構與服務 ▸ Sovereign Region(p73,僅 1 頁) |
| 官方考綱領域 | Describe Azure Architecture & Services(占比 35–40%) |
| 課程涵蓋範圍 | 主權區域 (Sovereign Region) 的定位與存在意義(課程僅以 1 頁帶過)。 |
| 本文補充範圍 | 1. 深入展開 Azure Government(美國專屬)與 Azure China(世紀互聯 21Vianet 營運)的資格、隔離與 Portal 端點差異。2. 釐清主權雲的實體與網路完全隔離(帳號無法跨區登入)。3. 補充 Trust Center vs Service Trust Portal(Compliance Manager) 的合規工具分工。4. 對照 AWS GovCloud (US) 與中國區的隔離設計。 |
⚠️ 考綱變更:本主題所涉之合規工具以 Microsoft Learn 現行名稱為準(Service Trust Portal、Compliance Manager 現隸屬 Microsoft Purview)。
明天 Day 4,我們將進入兵器庫——Azure 管理工具全貌(Portal / CLI / PowerShell / Cloud Shell),看看架構師如何依據跨平台自動化與管理需求,挑選最適合的作戰武器!
明天 Day 4,我們將進入兵器庫——Azure 管理工具全貌(Portal / CLI / PowerShell / Cloud Shell),看看架構師如何依據跨平台自動化與管理需求,挑選最適合的作戰武器!