A virtualised Trusted Platform Module within a VM. On confidential VMs, the OS disk keys are bound to it by confidential disk encryption.
Also called virtual Trusted Platform Module.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains vTPM in context, with comparison tables and the common traps.
Terms in this definition
- Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
- OS disk
Each VM has one; it is a managed disk with the operating system on it (C: under Windows) and is kept when the VM is resized or redeployed.
- Confidential disk encryption
Available just for confidential VMs, this encrypts the OS disk with keys bound to that VM's TPM, meaning the disk is unreadable anywhere else.
Related terms
- Guest Attestation extension
Lets Azure monitor a VM's boot integrity by passing its vTPM boot measurements to Azure Attestation. The VM also needs Secure Boot and vTPM switched on and must be able to reach the
AzureAttestationservice tag outbound. - Trusted launch
A free security type for Generation 2 Azure VMs on supported sizes, providing Secure Boot, a vTPM and boot integrity monitoring. Hardware memory encryption is what confidential VMs add beyond it.
- Trusted launch Secure Boot
Within trusted launch, the protection that blocks any boot loader, kernel or kernel driver lacking a valid signature, so unsigned images won't start. Guest attestation needs it enabled together with vTPM.