A free security type for Generation 2 Azure VMs on supported sizes, providing Secure Boot, a vTPM and boot integrity monitoring. Hardware memory encryption is what confidential VMs add beyond it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Trusted launch in context, with comparison tables and the common traps.
Terms in this definition
- Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
- HTTP / HTTPS
The protocols of the web, with HTTPS being HTTP secured by TLS.
- vTPM
A virtualised Trusted Platform Module within a VM. On confidential VMs, the OS disk keys are bound to it by confidential disk encryption.
- Boot integrity monitoring
Trusted launch feature in which the Guest Attestation extension remotely confirms that a VM booted cleanly; Defender for Cloud raises an alert if attestation fails.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- Architecture Definition Document
A key deliverable bringing together the main architecture artifacts across the four domains for every relevant state: baseline, transition and target. It sets out, in qualitative terms, what the architect intends.
Related terms
- Managed image
A type of image in Azure that can be brought into Windows 365 as a custom image. Trusted Launch isn't supported for managed images, so the VM behind the image needs the Standard security type.
- Trusted launch Secure Boot
Within trusted launch, the protection that blocks any boot loader, kernel or kernel driver lacking a valid signature, so unsigned images won't start. Guest attestation needs it enabled together with vTPM.