Digital Sovereignty Starts with Authentication

Digital sovereignty: on-premise Kerberos authentication for managed mobile devices

Lukas Schönbächler · January 14, 2026 · 8 min read

Why this matters

Most European organisations now run every login and every document through a handful of US cloud providers. That places foreign law, foreign politics, and someone else’s operations between your employees and their work. 2025 showed what that costs:

  • In June 2025, Microsoft France told the French Senate under oath that it cannot guarantee European data stays out of US hands. The CLOUD Act reaches data wherever a US provider stores it.
  • Cloud identity is a single point of failure: two incidents in 2025 (February and October) took Microsoft Entra ID sign-in down globally. Every app behind it stopped authenticating.
  • Schleswig-Holstein is removing Microsoft from 30,000 government workstations and expects to save over 15 million euros in licence costs in 2026. Digital sovereignty has moved from position papers to procurement.
  • Authentication is where sovereignty is won or lost: whoever operates your identity provider controls access to everything behind it.
  • Mobile SSO does not require a US-operated cloud. On-premise Kerberos with certificates keeps the entire authentication path inside your network and your jurisdiction, with any MDM.

For years, digital sovereignty was a topic for panel discussions: theoretically important, practically ignored. 2025 changed that. The warnings became court testimony, executive orders, and outage post-mortems. If your mobile fleet authenticates through a US-operated cloud identity service, last year handed you three concrete reasons to reconsider, and one architectural way out.

2025: the year the warnings became evidence

June 10, 2025, French Senate. Anton Carniaux, director of public and legal affairs at Microsoft France, was asked under oath whether he could guarantee that French citizens’ data would never be transmitted to US authorities without explicit French authorisation. His answer: «No, I cannot guarantee it.» He added that Microsoft resists requests it considers unfounded, and that the scenario had not yet occurred. The honesty is to his credit. The legal position it describes is the point: under the US CLOUD Act, a US provider can be compelled to hand over data regardless of where it is stored. Microsoft’s EU Data Boundary keeps European data resident in Europe, but residency is not jurisdiction. The Senate got that confirmed on the record.

February to May 2025, the ICC episode. After a US executive order sanctioned the chief prosecutor of the International Criminal Court in February, press reports in May said he had lost access to his Microsoft email account and moved to a Swiss provider. Microsoft disputes having cut the service. What is not disputed is the effect: the Dutch government began formally reassessing its dependence on US technology providers, and «digital sovereignty» entered parliamentary debates across Europe. The episode demonstrated the mechanism that matters: sanctions law binds US vendors, and access to your infrastructure can become collateral in someone else’s geopolitics.

Two authentication outages. On February 25, 2025, a DNS cleanup at Microsoft removed a domain used by Entra ID’s seamless single sign-on. For over an hour, cloud sign-in failed globally; nobody’s on-premises domain controllers were consulted, because the cloud path does not ask them. On October 29, 2025, a configuration error in Azure Front Door took Microsoft 365 and Entra ID down for the better part of a working day, with airlines and retailers reporting frozen internal systems. Neither incident was an attack. Both were routine operational mistakes at a vendor you cannot audit and cannot escalate beyond a status page.

Schleswig-Holstein votes with its budget. The northern German state decided in April 2024 to move its administration off the Microsoft stack: LibreOffice instead of Office, Linux instead of Windows, Open-Xchange and Thunderbird instead of Exchange and Outlook, and a directory service to replace Active Directory. By October 2025 it had migrated 40,000 mailboxes; by December 2025, LibreOffice was the binding standard on roughly 80 percent of state workstations. The state expects to save over 15 million euros in licence costs in 2026. Whatever you think of the approach, it settled one argument: a European public administration can run without the default stack.

2025 in Four Exhibits 10 JUN 2025 · FRENCH SENATE, UNDER OATH «No, I cannot guarantee it.» Microsoft France’s legal director, asked whether French data can be kept from US authorities. The CLOUD Act says no. 25 FEB + 29 OCT 2025 · GLOBAL Cloud sign-in failed twice Entra ID SSO broken by a routine DNS cleanup in February; an Azure Front Door config error cost most of a workday in October. FEB TO MAY 2025 · THE HAGUE ICC prosecutor loses email access Reported after US sanctions, disputed by Microsoft. Either way, the Dutch government began reassessing its US tech reliance. DEC 2025 · KIEL 30,000 desks leave Microsoft Schleswig-Holstein: LibreOffice standard on 80% of workstations, 15 million euros saved per year, Active Directory replacement next.

Figure 1: Four exhibits from one year. Testimony, sanctions, outages, and a completed exit: the sovereignty debate produced evidence in 2025. Sources are linked in the event descriptions above.

Why authentication is the sovereignty question

Most sovereignty debates focus on where files live. That misses the sharper dependency. Whoever operates your identity provider decides, operationally, whether anyone can log in at all. Files you can back up and re-host. Authentication is a live service: if it is down, sanctioned, or subpoenaed, the consequences arrive within minutes and apply to every application behind it.

The legal exposure follows the operator, not the data centre. The CLOUD Act of 2018 formalised what the Patriot Act era had already established in practice: US authorities can compel US providers to produce data under their control, wherever it sits. A European data centre run by a US company does not change the jurisdiction, which is exactly what the French Senate testimony confirmed. The Court of Justice of the EU reached the mirror-image conclusion in Schrems II back in 2020 when it struck down Privacy Shield over US surveillance law.

So the honest question for a CISO is not «is my data encrypted at rest in Frankfurt», but «which foreign legal orders and which vendor incidents can stop my organisation from authenticating». For a mobile fleet signing in through a cloud identity provider, the answer includes all of them.

The on-premise alternative already exists

Here is the part that gets lost in the sovereignty debate: for workplace authentication, the sovereign architecture is not something Europe needs to build. It is Kerberos against your own Active Directory, and most organisations already run it. The gap was never the server side. It was mobile: Android and iOS have no native way to participate in on-premises Kerberos, which is how fleets ended up authenticating through the cloud in the first place.

That gap is closable at the application layer. Hypergate Authenticator puts a Kerberos client on managed Android and iOS devices: the device obtains its ticket directly from your domain controller using certificate-based pre-authentication (PKINIT), with certificates issued by your own CA through your MDM. From there, browsers and business apps get single sign-on to on-premises resources. The complete authentication path, from credential to ticket to application, runs inside your network, under your jurisdiction, operated by you. It works in fully air-gapped environments, which is the strongest sovereignty statement an architecture can make: it does not need the internet at all, let alone the foreign cloud.

Sovereignty also has a second axis: vendor lock-in. An authentication layer tied to one UEM quietly removes your freedom to change device management vendors. Hypergate is deliberately MDM-agnostic: it is configured through standard managed configurations and works the same under Intune, Workspace ONE, Ivanti, SOTI, or any other Android Enterprise or iOS UEM. Your identity architecture stops being a reason you cannot leave a vendor, on either layer.

Cloud identity pathOn-premise Kerberos path
Where credentials are verifiedVendor cloud (US operator)Your domain controllers
Governing jurisdictionUS (CLOUD Act applies to operator)Yours
Blast radius of vendor outageAll sign-ins, all apps (Feb 25 and Oct 29, 2025)None: no cloud dependency in the auth path
Works air-gappedNoYes
Sanctions exposureOperator must comply with US executive ordersSoftware you operate keeps running
MDM couplingOften bundled with vendor ecosystemAny UEM via managed configuration
One Border, Two Authentication Paths US-operated cloud IdP CLOUD Act · sanctions outages of Feb + Oct 2025 Your network · your jurisdiction Managed device Hypergate, PKINIT Your domain controller Kerberos ticket, your CA On-prem app SSO Authentication never crosses the border. No internet required: works air-gapped. The cloud path exits your jurisdiction on every single login, even when the app is ten metres from the user. ✗ = border crossing you cannot control

Figure 2: One border. The cloud identity path crosses it on every login; the on-premise Kerberos path never leaves your network.

Sovereignty means operational control, not purity

A clarification, because sovereignty debates attract absolutism: Active Directory is Microsoft software too. The difference is not the vendor’s passport, it is who operates the system and what happens when the relationship is stressed. Software you run on your own hardware keeps working through a vendor outage, a sanctions order, or a contract dispute. A cloud service does not. Schleswig-Holstein can take years replacing Active Directory precisely because the on-premises stack keeps running while they do it; nobody can switch it off remotely. That is the working definition of digital sovereignty worth having: the ability to operate, and the ability to leave, on your own schedule.

The same logic applies whether your directory stays Active Directory for the next decade or migrates to something else: Kerberos is an open protocol, and an authentication architecture built on it, with certificates from your own CA, moves with you.

Where this leaves you

You do not need to copy Schleswig-Holstein to act on 2025’s lessons. The pragmatic first step is smaller: inventory which of your authentication flows depend on a US-operated cloud service, starting with mobile. If your phones and tablets can only reach on-premises applications through a cloud identity provider, you have imported CLOUD Act jurisdiction, sanctions exposure, and someone else’s outages into every mobile login. Moving mobile authentication onto on-premises Kerberos removes that dependency with the infrastructure you already own, works with the MDM you already have, and leaves every future option, including a directory migration, open.


Want authentication that answers only to you?

Hypergate Authenticator brings on-premise Kerberos SSO to managed Android and iOS: your domain controllers, your CA, your jurisdiction, any MDM. Built and operated from Switzerland.

Other Stories