Skip to content

Air-Gapped Architecture Design

Air-Gapped Architecture

Air-Gapped Architecture showing secure zones, data diodes, and offline update mechanisms Figure 1: Air-gapped Azure Local architecture with secure transfer mechanisms

Design and implement completely isolated Azure Local deployments with zero cloud connectivity, manual processes, and complete operational autonomy.


  • Physical isolation from cloud
  • No internet connectivity
  • Internal networks only
  • One-way transfer gates
  • Management domain (admin access)
  • Application domain (user workloads)
  • Data domain (sensitive information)
  • Update staging domain


  • USB storage devices
  • Removable media
  • Secure drives
  • Manual export/import processes
  • Integrity verification
  • Cryptographic signatures
  • Audit trails
  • Quarantine zone
  • Virus scanning
  • Content inspection
  • Change tracking

  • Local control plane
  • No cloud backup
  • Complete self-sufficiency
  • Manual administration
  • All data local
  • No external replication
  • Complete isolation
  • Local DR capability
  • Local telemetry
  • On-premises analytics
  • Local log storage
  • No cloud ingestion

  • Manual health checks
  • Local troubleshooting only
  • Offline documentation
  • No telemetry support

See also: Certificate Management