Loading...

Private Preview: Introducing DCesv5 and ECesv5-series Confidential VMs with Intel TDX

Private Preview: Introducing DCesv5 and ECesv5-series Confidential VMs with Intel TDX

Today, we’re excited to announce the expansion of our Confidential VM family with the launch of the DCesv5-series and ECesv5-series in private preview. Featuring 4th Gen Intel® Xeon® Scalable processors, these VMs are backed by an all-new hardware-based Trusted Execution Environment called Intel® Trust Domain Extensions (TDX). Organizations can use these VMs to seamlessly bring confidential workloads to the cloud without any code changes to their applications.

 

At Azure, we strive to ensure your data is always under your control with the most-comprehensive enterprise compliance and security safeguards. Intel TDX helps harden the virtualized environment to deny the hypervisor and other host management code access to VM memory and state, including the cloud operator. Intel TDX helps assure workload integrity and confidentiality by mitigating a wide range of software and hardware attacks, including intrusion or inspection by software running in other VMs.

 

Trusted Execution Environments continue to rapidly improve in performance

 

On compute-intensive workloads, the new virtual machines protected with Intel TDX perform on-par with general-purpose D16sv5 virtual machines. Throughout the preview, we plan to further optimize and tune, and will release additional performance benchmarks for CPU, memory, and IO-intensive workloads.

 

mmcrey_0-1682114170391.png

 

Confidential virtual machines support a broad range of workloads

 

We continue to raise the security bar for general-purpose and memory-optimized virtual machines. This offering enables organizations to further fortify code and data, particularly for complex artificial intelligence models, training data, and inference data. Confidential VMs continue to demonstrate strength with migrating sensitive databases, enterprise applications, as well as mission-critical SAP instances.

 

  • DCesv5 series offers up to 96 vCPUs and range between 4 GiBs of memory, up to 384 GiBs
  • ECesv5 series offers up to 64 vCPUs and range between 8 GiBs of memory, up to 512 GiBs

 

New remote attestation capabilities

 

Since organizations will want to attest the environment, we provide capabilities to retrieve hardware evidence for cryptographic verification of the TEE state and third-party root of trust. Organizations will have native support for attestation with Microsoft Azure Attestation, and we’ve worked closely with Intel on support for “Project Amber”, Intel’s upcoming trust service, helping enterprises that want to enforce operator-independence and separation of duties deploying Confidential Computing.

 

Expanding support for confidentiality with ecosystem partners

 

We collaborated with the Confidential Computing Consortium to provide a first-class Linux experience for the platform. Throughout the preview, Canonical Ubuntu Server 22.04 LTS, SUSE Linux Enterprise Server 15 SP5 and SUSE Linux Enterprise Server for SAP 15 SP5 are available for testing. Canonical and SUSE consistently exhibit reliability and security for enterprise workloads. We are working on adding support for Red Hat Enterprise Linux (RHEL) and Windows support.

 

Sign up for the preview

 

Azure has built this product from the ground up in conjunction with a wide array of security-minded cloud professionals – from those seeking simple and highly secured cloud compute, to those responsible for their organizations’ most regulated and confidential data. Sign-up for the preview today.

 

Helpful Links

Published on:

Learn more
Azure Confidential Computing Blog articles
Azure Confidential Computing Blog articles

Azure Confidential Computing Blog articles

Share post:

Related posts

Adams Bridge: An Accelerator for Post-Quantum Resilient

The name Adams Bridge is inspired by the mythological structure which was said to span a vast gulf between two landmasses. In the realm of cry...

1 year ago

General Availability: Azure confidential VMs with NVIDIA H100 Tensor Core GPUs

Today, we are announcing the general availability of Azure confidential virtual machines (VMs) with NVIDIA H100 Tensor core GPUs. These VMs co...

1 year ago

Azure AI Confidential Inferencing: Technical Deep-Dive

Generative AI powered by Large Language Models (LLMs) has revolutionized the way we interact with technology. Through chatbots, co-pilots, and...

1 year ago

Verify the integrity of Azure Confidential Ledger transactions with receipts and application claims

In today's digital landscape, the integrity and confidentiality of transactional data are paramount. Microsoft’s Azure Confidential Ledger off...

2 years ago

Memory Protection for AI ML Model Inferencing

This article was originally posted on Confidential Container Project's blog by Suraj Deshmukh & Pradipta Banerjee. Read the original artic...

2 years ago

General Availability: Azure Managed HSM Backup/Restore when Storage is Behind a Private Endpoint

We are excited to announce the General Availability of support for Azure Key Vault Managed HSM backup/restore when the sto...

2 years ago

Public Preview: Azure Managed HSM Backup/Restore when Storage Account is Behind a Private Endpoint

We are excited to announce the Public Preview of support for Azure Key Vault Managed HSM backup/restore when the storage accoun...

2 years ago

General Availability: Managed HSM Networking Settings in Azure Portal

We are excited to announce the General Availability of networking settings for Azure Key Vault Managed HSM on the Azure po...

2 years ago

New innovations in confidential computing from Azure at Ignite 2023

Azure has been a pioneer and leader in the field of confidential computing, offering the most comprehensive portfolio of products and services...

2 years ago

Announcing Azure confidential VMs with NVIDIA H100 Tensor Core GPUs in Preview

Today, we are excited to announce the preview of Azure confidential VMs with NVIDIA H100 Tensor core GPUs.  These VMs are ideal for ...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.