Available just for confidential VMs, this encrypts the OS disk with keys bound to that VM's TPM, meaning the disk is unreadable anywhere else.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Confidential disk encryption in context, with comparison tables and the common traps.
Terms in this definition
- Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
- OS disk
Each VM has one; it is a managed disk with the operating system on it (C: under Windows) and is kept when the VM is resized or redeployed.
- TPM
Tokens per minute, the measure for Azure OpenAI quota and deployment rate limits. Going over it produces an HTTP 429 response.
Related terms
- vTPM
A virtualised Trusted Platform Module within a VM. On confidential VMs, the OS disk keys are bound to it by confidential disk encryption.