Does Microsoft Entra ID Work in China? The 21Vianet Sovereign Cloud, Identity Data Residency & PIPL Cross-Border
Microsoft Entra ID (formerly Azure Active Directory) is available in mainland China — but through a separate, physically isolated sovereign cloud, Microsoft Entra ID in Microsoft Azure operated by 21Vianet (世纪互联), with its own endpoints (login.partner.microsoftonline.cn), not the global service at login.microsoftonline.com. The real decision for a China-facing deployment isn't sign-in speed — it's residency: a directory is personal information (user accounts, user principal names, phone numbers, sign-in logs), and running your global Entra tenant for China identities keeps that data offshore, a PIPL cross-border transfer, while the data-resident lawful path is the 21Vianet-operated China cloud. A compliance-first look at the two instances, identity-data residency, CSL Article 39 (formerly Article 37), the cross-border question, and the lawful in-country path.
Does Microsoft Entra ID work in China?
Yes — Microsoft Entra ID is available in mainland China, but through a separate, physically isolated sovereign cloud: Microsoft Entra ID in “Microsoft Azure operated by 21Vianet” (世纪互联), not the global service you reach at login.microsoftonline.com. Microsoft documents this China national cloud with its own authentication endpoint (login.partner.microsoftonline.cn), its own Azure portal, and its own app registrations, operated inside the mainland through a partnership with 21Vianet.
Because a lawful in-country instance exists, the real decision is identity-data residency, not speed. Entra ID is a directory — user accounts, user principal names, phone numbers, group membership, and sign-in logs, all personal information under Chinese law. Run that on the global tenant for China users and the directory sits in a Microsoft geography outside the mainland, a PIPL cross-border transfer (and, for a CII operator, a residency problem under Cybersecurity Law Article 39 (formerly Article 37)); larger or sensitive transfers can add a CAC data-export security assessment. The data-resident path is the 21Vianet-operated China national cloud — subject to availability and feature parity, which you confirm with Microsoft and 21Vianet.
21YunBox maps the instance choice, localizes your identity onto the data-resident China path, and delivers the China-facing apps that authenticate against it in-country on ICP-filed infrastructure — so it runs legally in the mainland, and we never use or suggest circumvention of any kind. Treat the specifics as a risk to confirm with counsel.
What Microsoft Entra ID's own documentation says about China
| Fact | Primary source |
|---|---|
| Microsoft Entra ID is deployed in a China national cloud operated by 21Vianet. Microsoft Learn states national clouds are “physically isolated instances of Azure” and lists “Microsoft Azure operated by 21Vianet” among the national clouds in which “Microsoft Entra ID is deployed.” | Microsoft Learn — “Microsoft Entra authentication & national clouds” (learn.microsoft.com), updated 2026-06-15, retrieved 2026-10-08 |
| The China cloud has its own endpoints, separate from global Entra ID. Microsoft lists the China authentication endpoint as “https://login.partner.microsoftonline.cn” for “Microsoft Entra China operated by 21Vianet,” distinct from the global “https://login.microsoftonline.com,” and notes you are “required to register your application separately in each Azure portal.” | Microsoft Learn — “Microsoft Entra authentication & national clouds” (learn.microsoft.com), updated 2026-06-15, retrieved 2026-10-08 |
| On the China national cloud, directory data stays in-country; on the global service it does not. Microsoft's data-residency page documents the sovereign/national cloud for China as holding data “at rest, in the target location. No exceptions,” operated “through a partnership with 21Vianet,” while the public geo-locations a global tenant can choose (Asia/Pacific, EMEA, North America, Japan, Australia, Worldwide) do not include mainland China. | Microsoft Learn — “Microsoft Entra ID and data residency” (learn.microsoft.com), updated 2026-06-15, retrieved 2026-10-08 |
| Using the global tenant for China identities is a cross-border transfer. Sending a Chinese user's identity personal information to an Entra directory hosted outside the mainland triggers PIPL Chapter III (Articles 38–43): notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — with in-country storage under Article 40 (and Cybersecurity Law Article 39 (formerly Article 37)) for CII operators. | Personal Information Protection Law of the PRC, Chapter III, Articles 38–43 (cac.gov.cn), retrieved 2026-10-08 |
Sources verified by the 21YunBox compliance team on 2026-10-08.
For a mainland-China audience, the first thing to settle about Microsoft Entra ID is not how fast a sign-in completes — it is which Entra you mean. Microsoft runs two separate instances that matter here: the global Microsoft Entra ID (formerly Azure Active Directory) most teams reach at login.microsoftonline.com, and a distinct, physically isolated China national cloud — Microsoft Entra ID in “Microsoft Azure operated by 21Vianet” (世纪互联) — with its own authentication endpoint at login.partner.microsoftonline.cn, its own Azure portal and sign-up, and data kept inside the mainland. So the honest answer to “does Microsoft Entra ID work in China?” is yes — but through a specific national cloud, on a specific footing.
Because a lawful in-country instance already exists, the decision moves off the speed axis and onto a data one. Entra ID is a directory: it holds personal information — user accounts, display names, user principal names and email addresses, phone numbers used for multifactor authentication, group and role membership, and the sign-in and audit logs that record who signed in from where. Run your identity on the global service from the mainland and that directory data sits in a Microsoft geography fixed when the tenant was created — none of them mainland China — which is a cross-border transfer under PIPL; stand it up on the 21Vianet-operated China cloud and the data stays in-country. Which instance you choose, and how you deliver the apps that authenticate against it, is the compliance question — not the sign-in latency.
Microsoft Entra ID in China at a glance
| What decides it | In Microsoft's own terms — and China's law |
|---|---|
| What it is | Microsoft Entra ID (formerly Azure Active Directory) — Microsoft's cloud identity and access service: the directory, single sign-on, multifactor authentication, and Conditional Access behind your apps. Two separate instances matter for China: the global service, and a distinct, physically isolated China national cloud, Microsoft Entra ID in "Microsoft Azure operated by 21Vianet" (世纪互联). |
| Is it available in the mainland? | Yes — through the separate, physically isolated China national cloud. Microsoft documents "Microsoft Entra China operated by 21Vianet" with its own authentication endpoint (login.partner.microsoftonline.cn) and its own Azure portal (portal.azure.cn), and you register applications separately in it. The global service at login.microsoftonline.com is a different instance and is not connected to it. |
| Where the identity data lives | On the 21Vianet-operated China cloud, Microsoft documents directory data kept "at rest, in the target location. No exceptions." On the global service, a tenant's directory data sits in a geography fixed at creation — Asia/Pacific, EMEA, North America, Japan, Australia, or Worldwide — none of which is mainland China, so China users' identity data (accounts, user principal names, phone numbers, sign-in logs) sits offshore. |
| Cross-border & residency | Moving China users' identity personal information to the global tenant is a cross-border transfer under PIPL (Articles 38–43: notice, a separate consent, one transfer mechanism). For a critical information infrastructure operator, in-country storage is required under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37); larger-volume or sensitive transfers can add a CAC data-export security assessment. |
| The lawful path | Stand up identity on the 21Vianet-operated China national cloud (or otherwise keep the directory data in-country), and deliver the China-facing apps that authenticate against it on ICP-filed, in-country infrastructure. 21YunBox maps the instance choice, localizes your identity onto the data-resident path, and delivers it in-country — subject to the China cloud's availability and feature parity, which you confirm with Microsoft and 21Vianet. |
Availability: a physically isolated China national cloud, operated by 21Vianet
Microsoft Entra ID’s presence in the mainland is set in Microsoft’s own documentation, not by a load-time test. Microsoft Learn’s “Microsoft Entra authentication & national clouds” lists “Microsoft Azure operated by 21Vianet” among the national clouds in which “Microsoft Entra ID is deployed,” and describes those national clouds as “physically isolated instances of Azure” that are “designed to make sure that data residency, sovereignty, and compliance requirements are honored within geographical boundaries.” The China cloud has its own authentication endpoint — login.partner.microsoftonline.cn — entirely separate from the global login.microsoftonline.com, and its own Azure portal at portal.azure.cn.
Two things follow. First, the China cloud is a separate instance: “Each cloud instance is separate from the others and has its own environment and endpoints,” and Microsoft notes “you’re required to register your application separately in each Azure portal that’s specific to the environment” — so there is no tenant setting that flips a global directory into China. Second, Microsoft warns that “some services and features in the global Azure cloud might be unavailable in other cloud instances like the national clouds,” so which Entra capabilities and connectors are offered inside the China cloud is something you confirm directly with Microsoft and 21Vianet before you build. For that reason this page publishes no first-party China latency figure for Microsoft Entra ID: a lawful in-country instance already exists, so speed is not the axis the decision turns on.
The residency question: your directory is personal information
The gate that actually decides a China Entra ID deployment is where the identity data lives. A directory is not an abstraction — it is a store of personal information: user accounts, display names, user principal names and email addresses, phone numbers used for multifactor authentication, group and role membership, and sign-in and audit logs. Run that on the global service for users in China and the directory sits in a Microsoft geography fixed when the tenant was created — Microsoft’s own data-residency page lists those public geo-locations as Asia/Pacific, EMEA, North America, Japan, Australia, and Worldwide, none of which is mainland China. Keeping Chinese users’ identity data there is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, not Microsoft: Chapter III (Articles 38–43) requires notice, a separate consent distinct from the user’s agreement to sign in, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.
Underneath that sits residency. A critical information infrastructure operator or a large-volume handler must store personal information collected in China inside the mainland (PIPL Article 40, with Cybersecurity Law Article 39 (formerly Article 37)) — a duty the global, offshore directory structurally cannot meet. By contrast, Microsoft documents the China national cloud as holding data “at rest, in the target location. No exceptions,” operated “through a partnership with 21Vianet.” And where volumes or data sensitivity cross the thresholds, the transfer itself needs a CAC data-export security assessment before it may proceed. How heavy each of these is scales with your data and your role, which is why it belongs with counsel rather than a default assumption — a risk to confirm against what you actually deploy.
The data-resident path: the 21Vianet-operated China national cloud
The lawful, in-country footing is the one Microsoft already documents: the China national cloud, Microsoft Entra ID in “Microsoft Azure operated by 21Vianet,” where directory data is kept in the mainland. On that path the cross-border question does not arise in the same way, because the identity data does not leave. The work is to plan the deployment onto it — the China cloud is a separate instance with its own sign-up and its own app registrations, so tenants, users, groups, Conditional Access policies, and the applications that federate to it are stood up there rather than switched over from a global tenant — and to confirm, up front, that the Entra capabilities your access model depends on are available in the China cloud. That availability-and-parity check is not a formality; it is the step that tells you whether the data-resident path carries your identity design as-is or needs adjustment.
The lawful path — map, localize, deliver
There is a lawful way to run Microsoft Entra ID for Chinese users, and it has a clear shape: the identity data stays in-country on the 21Vianet-operated China national cloud, and the China-facing apps that authenticate against it are themselves delivered compliantly inside the mainland. That second half is easy to miss. Identity is a hub — a portal, intranet, or customer app that signs users in through Entra is a public-facing service in China, so it carries an ICP filing (备案) duty and needs compliant in-country delivery like any other China property. A sign-in that resolves to a directory kept in-country, but hangs off an unfiled, offshore front end, has only solved half the problem.
That is the footing 21YunBox owns, and it is more than advice. Our China team does three things on it: we map the instance choice and your PIPL and residency exposure, so you know which Entra you should be running and what each option obliges; we localize your identity onto the data-resident path — standing up and integrating the 21Vianet-operated China national cloud, or otherwise keeping the directory data in-country, in place of a global tenant that cannot meet the residency duty; and we deliver the China-facing apps that sign in against it in-country on ICP-filed infrastructure — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is an identity deployment that runs legally and compliantly for your users in China. What we do not do is route anyone around anyone’s terms or any network control: this is a lawful in-country deployment, built on the China cloud Microsoft and 21Vianet already provide — we never use or suggest circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — Article 39 (formerly Article 37) and data localization
- China’s data-export security assessment measures
