Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Microsoft Entra ID Work in China? The 21Vianet Sovereign Cloud, Identity Data Residency & PIPL Cross-Border

Microsoft Entra ID (formerly Azure Active Directory) is available in mainland China — but through a separate, physically isolated sovereign cloud, Microsoft Entra ID in Microsoft Azure operated by 21Vianet (世纪互联), with its own endpoints (login.partner.microsoftonline.cn), not the global service at login.microsoftonline.com. The real decision for a China-facing deployment isn't sign-in speed — it's residency: a directory is personal information (user accounts, user principal names, phone numbers, sign-in logs), and running your global Entra tenant for China identities keeps that data offshore, a PIPL cross-border transfer, while the data-resident lawful path is the 21Vianet-operated China cloud. A compliance-first look at the two instances, identity-data residency, CSL Article 39 (formerly Article 37), the cross-border question, and the lawful in-country path.

Does Microsoft Entra ID work in China?

Yes — Microsoft Entra ID is available in mainland China, but through a separate, physically isolated sovereign cloud: Microsoft Entra ID in “Microsoft Azure operated by 21Vianet” (世纪互联), not the global service you reach at login.microsoftonline.com. Microsoft documents this China national cloud with its own authentication endpoint (login.partner.microsoftonline.cn), its own Azure portal, and its own app registrations, operated inside the mainland through a partnership with 21Vianet.

Because a lawful in-country instance exists, the real decision is identity-data residency, not speed. Entra ID is a directory — user accounts, user principal names, phone numbers, group membership, and sign-in logs, all personal information under Chinese law. Run that on the global tenant for China users and the directory sits in a Microsoft geography outside the mainland, a PIPL cross-border transfer (and, for a CII operator, a residency problem under Cybersecurity Law Article 39 (formerly Article 37)); larger or sensitive transfers can add a CAC data-export security assessment. The data-resident path is the 21Vianet-operated China national cloud — subject to availability and feature parity, which you confirm with Microsoft and 21Vianet.

21YunBox maps the instance choice, localizes your identity onto the data-resident China path, and delivers the China-facing apps that authenticate against it in-country on ICP-filed infrastructure — so it runs legally in the mainland, and we never use or suggest circumvention of any kind. Treat the specifics as a risk to confirm with counsel.

What Microsoft Entra ID's own documentation says about China

FactPrimary source
Microsoft Entra ID is deployed in a China national cloud operated by 21Vianet. Microsoft Learn states national clouds are “physically isolated instances of Azure” and lists “Microsoft Azure operated by 21Vianet” among the national clouds in which “Microsoft Entra ID is deployed.” Microsoft Learn — “Microsoft Entra authentication & national clouds” (learn.microsoft.com), updated 2026-06-15, retrieved 2026-10-08
The China cloud has its own endpoints, separate from global Entra ID. Microsoft lists the China authentication endpoint as “https://login.partner.microsoftonline.cn” for “Microsoft Entra China operated by 21Vianet,” distinct from the global “https://login.microsoftonline.com,” and notes you are “required to register your application separately in each Azure portal.” Microsoft Learn — “Microsoft Entra authentication & national clouds” (learn.microsoft.com), updated 2026-06-15, retrieved 2026-10-08
On the China national cloud, directory data stays in-country; on the global service it does not. Microsoft's data-residency page documents the sovereign/national cloud for China as holding data “at rest, in the target location. No exceptions,” operated “through a partnership with 21Vianet,” while the public geo-locations a global tenant can choose (Asia/Pacific, EMEA, North America, Japan, Australia, Worldwide) do not include mainland China. Microsoft Learn — “Microsoft Entra ID and data residency” (learn.microsoft.com), updated 2026-06-15, retrieved 2026-10-08
Using the global tenant for China identities is a cross-border transfer. Sending a Chinese user's identity personal information to an Entra directory hosted outside the mainland triggers PIPL Chapter III (Articles 38–43): notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — with in-country storage under Article 40 (and Cybersecurity Law Article 39 (formerly Article 37)) for CII operators. Personal Information Protection Law of the PRC, Chapter III, Articles 38–43 (cac.gov.cn), retrieved 2026-10-08

Sources verified by the 21YunBox compliance team on 2026-10-08.

For a mainland-China audience, the first thing to settle about Microsoft Entra ID is not how fast a sign-in completes — it is which Entra you mean. Microsoft runs two separate instances that matter here: the global Microsoft Entra ID (formerly Azure Active Directory) most teams reach at login.microsoftonline.com, and a distinct, physically isolated China national cloud — Microsoft Entra ID in “Microsoft Azure operated by 21Vianet” (世纪互联) — with its own authentication endpoint at login.partner.microsoftonline.cn, its own Azure portal and sign-up, and data kept inside the mainland. So the honest answer to “does Microsoft Entra ID work in China?” is yes — but through a specific national cloud, on a specific footing.

Because a lawful in-country instance already exists, the decision moves off the speed axis and onto a data one. Entra ID is a directory: it holds personal information — user accounts, display names, user principal names and email addresses, phone numbers used for multifactor authentication, group and role membership, and the sign-in and audit logs that record who signed in from where. Run your identity on the global service from the mainland and that directory data sits in a Microsoft geography fixed when the tenant was created — none of them mainland China — which is a cross-border transfer under PIPL; stand it up on the 21Vianet-operated China cloud and the data stays in-country. Which instance you choose, and how you deliver the apps that authenticate against it, is the compliance question — not the sign-in latency.

Microsoft Learn article 'Microsoft Entra authentication & national clouds' showing the Microsoft Entra authentication endpoints table, which lists 'Microsoft Entra China operated by 21Vianet' with endpoint https://login.partner.microsoftonline.cn, separate from 'Microsoft Entra ID (global service)' at https://login.microsoftonline.com
Microsoft's own developer documentation, “Microsoft Entra authentication & national clouds,” lists the base URLs for the Microsoft Entra authentication endpoints in each national cloud. It gives “Microsoft Entra China operated by 21Vianet” its own endpoint — “https://login.partner.microsoftonline.cn” — separate from the “Microsoft Entra ID (global service)” at “https://login.microsoftonline.com.” The China cloud is a distinct, isolated instance with its own sign-in. Source: learn.microsoft.com — Microsoft Entra authentication & national clouds

Microsoft Entra ID in China at a glance

What decides it In Microsoft's own terms — and China's law
What it is Microsoft Entra ID (formerly Azure Active Directory) — Microsoft's cloud identity and access service: the directory, single sign-on, multifactor authentication, and Conditional Access behind your apps. Two separate instances matter for China: the global service, and a distinct, physically isolated China national cloud, Microsoft Entra ID in "Microsoft Azure operated by 21Vianet" (世纪互联).
Is it available in the mainland? Yes — through the separate, physically isolated China national cloud. Microsoft documents "Microsoft Entra China operated by 21Vianet" with its own authentication endpoint (login.partner.microsoftonline.cn) and its own Azure portal (portal.azure.cn), and you register applications separately in it. The global service at login.microsoftonline.com is a different instance and is not connected to it.
Where the identity data lives On the 21Vianet-operated China cloud, Microsoft documents directory data kept "at rest, in the target location. No exceptions." On the global service, a tenant's directory data sits in a geography fixed at creation — Asia/Pacific, EMEA, North America, Japan, Australia, or Worldwide — none of which is mainland China, so China users' identity data (accounts, user principal names, phone numbers, sign-in logs) sits offshore.
Cross-border & residency Moving China users' identity personal information to the global tenant is a cross-border transfer under PIPL (Articles 38–43: notice, a separate consent, one transfer mechanism). For a critical information infrastructure operator, in-country storage is required under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37); larger-volume or sensitive transfers can add a CAC data-export security assessment.
The lawful path Stand up identity on the 21Vianet-operated China national cloud (or otherwise keep the directory data in-country), and deliver the China-facing apps that authenticate against it on ICP-filed, in-country infrastructure. 21YunBox maps the instance choice, localizes your identity onto the data-resident path, and delivers it in-country — subject to the China cloud's availability and feature parity, which you confirm with Microsoft and 21Vianet.

Availability: a physically isolated China national cloud, operated by 21Vianet

Microsoft Entra ID’s presence in the mainland is set in Microsoft’s own documentation, not by a load-time test. Microsoft Learn’s “Microsoft Entra authentication & national clouds” lists “Microsoft Azure operated by 21Vianet” among the national clouds in which “Microsoft Entra ID is deployed,” and describes those national clouds as “physically isolated instances of Azure” that are “designed to make sure that data residency, sovereignty, and compliance requirements are honored within geographical boundaries.” The China cloud has its own authentication endpoint — login.partner.microsoftonline.cn — entirely separate from the global login.microsoftonline.com, and its own Azure portal at portal.azure.cn.

Two things follow. First, the China cloud is a separate instance: “Each cloud instance is separate from the others and has its own environment and endpoints,” and Microsoft notes “you’re required to register your application separately in each Azure portal that’s specific to the environment” — so there is no tenant setting that flips a global directory into China. Second, Microsoft warns that “some services and features in the global Azure cloud might be unavailable in other cloud instances like the national clouds,” so which Entra capabilities and connectors are offered inside the China cloud is something you confirm directly with Microsoft and 21Vianet before you build. For that reason this page publishes no first-party China latency figure for Microsoft Entra ID: a lawful in-country instance already exists, so speed is not the axis the decision turns on.

The residency question: your directory is personal information

The gate that actually decides a China Entra ID deployment is where the identity data lives. A directory is not an abstraction — it is a store of personal information: user accounts, display names, user principal names and email addresses, phone numbers used for multifactor authentication, group and role membership, and sign-in and audit logs. Run that on the global service for users in China and the directory sits in a Microsoft geography fixed when the tenant was created — Microsoft’s own data-residency page lists those public geo-locations as Asia/Pacific, EMEA, North America, Japan, Australia, and Worldwide, none of which is mainland China. Keeping Chinese users’ identity data there is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, not Microsoft: Chapter III (Articles 38–43) requires notice, a separate consent distinct from the user’s agreement to sign in, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.

Underneath that sits residency. A critical information infrastructure operator or a large-volume handler must store personal information collected in China inside the mainland (PIPL Article 40, with Cybersecurity Law Article 39 (formerly Article 37)) — a duty the global, offshore directory structurally cannot meet. By contrast, Microsoft documents the China national cloud as holding data “at rest, in the target location. No exceptions,” operated “through a partnership with 21Vianet.” And where volumes or data sensitivity cross the thresholds, the transfer itself needs a CAC data-export security assessment before it may proceed. How heavy each of these is scales with your data and your role, which is why it belongs with counsel rather than a default assumption — a risk to confirm against what you actually deploy.

The data-resident path: the 21Vianet-operated China national cloud

The lawful, in-country footing is the one Microsoft already documents: the China national cloud, Microsoft Entra ID in “Microsoft Azure operated by 21Vianet,” where directory data is kept in the mainland. On that path the cross-border question does not arise in the same way, because the identity data does not leave. The work is to plan the deployment onto it — the China cloud is a separate instance with its own sign-up and its own app registrations, so tenants, users, groups, Conditional Access policies, and the applications that federate to it are stood up there rather than switched over from a global tenant — and to confirm, up front, that the Entra capabilities your access model depends on are available in the China cloud. That availability-and-parity check is not a formality; it is the step that tells you whether the data-resident path carries your identity design as-is or needs adjustment.

The lawful path — map, localize, deliver

There is a lawful way to run Microsoft Entra ID for Chinese users, and it has a clear shape: the identity data stays in-country on the 21Vianet-operated China national cloud, and the China-facing apps that authenticate against it are themselves delivered compliantly inside the mainland. That second half is easy to miss. Identity is a hub — a portal, intranet, or customer app that signs users in through Entra is a public-facing service in China, so it carries an ICP filing (备案) duty and needs compliant in-country delivery like any other China property. A sign-in that resolves to a directory kept in-country, but hangs off an unfiled, offshore front end, has only solved half the problem.

That is the footing 21YunBox owns, and it is more than advice. Our China team does three things on it: we map the instance choice and your PIPL and residency exposure, so you know which Entra you should be running and what each option obliges; we localize your identity onto the data-resident path — standing up and integrating the 21Vianet-operated China national cloud, or otherwise keeping the directory data in-country, in place of a global tenant that cannot meet the residency duty; and we deliver the China-facing apps that sign in against it in-country on ICP-filed infrastructure — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is an identity deployment that runs legally and compliantly for your users in China. What we do not do is route anyone around anyone’s terms or any network control: this is a lawful in-country deployment, built on the China cloud Microsoft and 21Vianet already provide — we never use or suggest circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Microsoft Entra ID available in mainland China?
Yes — through a separate, physically isolated sovereign cloud: Microsoft Entra ID in “Microsoft Azure operated by 21Vianet” (世纪互联), which Microsoft documents with its own authentication endpoint (login.partner.microsoftonline.cn), its own Azure portal (portal.azure.cn), and its own app registrations. That is a different instance from the global Entra ID at login.microsoftonline.com, and the two are not connected. Feature parity and availability can differ, so confirm the specifics with Microsoft and 21Vianet.
Can I just use my existing (global) Entra ID tenant for users in China?
You may be able to authenticate against it, but that is the compliance question, not a speed one. A global tenant keeps its directory data — user accounts, user principal names, phone numbers, sign-in logs, all personal information — in a Microsoft geography outside the mainland, so holding China users' identity data there is a cross-border transfer under PIPL (Articles 38–43: notice, a separate consent, and a transfer mechanism), and for a critical information infrastructure operator, in-country storage is required under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37). Larger or sensitive transfers can also need a CAC data-export security assessment. Confirm your exact obligations with counsel.
What's the data-resident, compliant path for Microsoft Entra ID in China?
Stand up identity on the 21Vianet-operated China national cloud (or otherwise keep the directory data in-country), where Microsoft documents data kept at rest in the target location, and deliver the China-facing apps that authenticate against it on ICP-filed, in-country infrastructure. 21YunBox maps the instance choice and your PIPL and residency exposure, localizes your identity onto the data-resident China path, and provides the in-country delivery — no rebuild and no re-platform. It is a lawful in-country deployment, not a way around anyone's terms or any network control.

ARTICLES RELATED TO MICROSOFT ENTRA ID

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.