Loading...

Announcing General Availability of Confidential VMs in Azure Virtual Desktop

Announcing General Availability of Confidential VMs in Azure Virtual Desktop

Today we are announcing the General Availability of several confidential VM and Trusted Launch security features via AVD Host Pool Provisioning.  

 

What are Confidential VMs? 

 

The AMD Azure EPYC SEV-SNP DCasV5 and ECasv5-series confidential VM series provides a hardware-based Trusted Execution Environment (TEE) with attestation capability by leveraging AMD SEV-SNP security features. Azure confidential VMs (CVMs) offer VM memory encryption with integrity protection, which strengthens guest protections to deny the hypervisor and other host management components code access to the VM memory and state. For additional CVM security benefits, please see the CVM documentation for more information. 

With this general availability, Windows 11 22H1 is now also supported in CVMs, adding to the list of already supported versions of 22H2 and other future versions of Windows 11. In addition, confidential OS Disk Encryption is available for confidential VMs, and Integrity monitoring is available during AVD Host Pool provisioning for both confidential VMs and Trusted Launch VMs.  

Confidential disk encryption is an additional layer of encryption that binds the disk encryption keys to the VM’s TPM and makes the disk content accessible only to the VM. For more information about disk encryption, please visit FAQ - Azure Disk Encryption for Windows VMs - Azure Virtual Machines | Microsoft Learn. 

Integrity monitoring allows cryptographic attestation and verification of VM boot integrity. It includes monitoring alerts for the VM booting because attestation failed with the defined baseline. For more information about integrity monitoring, please visit the Microsoft Defender for Cloud Integration section of Trusted Launch for Azure VMs documentation. 

 

What is Trusted Launch? 

Trusted Launch (TL) protects against advanced and persistent attack techniques. They allow for secure deployment of VMs with verified boot loaders, OS kernels, and drivers. In addition, they protect keys, certificates, and secrets in VMs. For more information about TL benefits, please see the Trusted Launch documentation. 

Therefore, we are pleased to announce that Trusted Launch is now enabled by default for all Windows images.  

 

How to deploy CVMs in AVD Host Pool Provisioning with these settings 

  • Select Confidential Virtual Machines from the Security Type dropdown in the AVD Host Pool Virtual Machine blade.

dereksu_0-1687888866648.png

 

  • Once Security Type is set to Confidential Virtual Machines, you will see the option to select Integrity Monitoring. 

 

suderek_1-1687825764301.png

 

 

 

  • Select any CVM compatible Windows 11 images from the Image dropdown. Scroll to Confidential compute encryption and select it for enabling OS Disk Encryption for your CVM. 

 

suderek_2-1687825764303.png

 

 

 

How Trusted Launch is enabled by default for non-Confidential Virtual Machines for any images. 

By default, the Security type will automatically change to Trusted Virtual Machines. This was done to meet the mandatory hardware requirements of Windows 11. For further information about this requirement, please see this reference on Windows 11 requirements.  

 

dereksu_0-1688149093373.png

 

Getting Started 

To get started, please visit Azure Virtual Desktop | Microsoft Azure to learn more about the various benefits AVD provides and to get started with your first deployment. 

Visit Create a host pool - Azure Virtual Desktop | Microsoft Learn to start deploying your first confidential VM in Azure Virtual Desktop through the Azure Portal. For more information about any of these features, please visit Azure Virtual Desktop security best practices - Azure | Microsoft Learn

 

Published on:

Learn more
Azure Virtual Desktop Blog articles
Azure Virtual Desktop Blog articles

Azure Virtual Desktop Blog articles

Share post:

Related posts

Storage migration: Combine Azure Storage Mover and Azure Data Box

Migrating storage from on-premises can be challenging. That’s why we are on a mission to make your migrations as simple as possible. We've dev...

25 minutes ago

Loop DDoS Attacks: Understanding the Threat and Azure's Defense

In the realm of cybersecurity, Distributed Denial-of-Service (DDoS) attacks are a significant concern. The recent holiday season has unveiled ...

8 hours ago

Azure Communication Services at Microsoft Build 2024

Join us in-person in Seattle or virtually for Microsoft Build 2024 from May 21 to 24. We're excited to share the latest updates from Azure Com...

9 hours ago

Azure Developer CLI (azd) – May 2024 Release

This post announces the May release of the Azure Developer CLI (`azd`), which includes a new demo mode, various .NET Aspire enhancements, and ...

9 hours ago

Join us at Build 2024: Get the latest on Azure Cosmos DB in Seattle or online!

Are you ready to dive into the future of AI and data innovation? Microsoft Build 2024 is just around the corner, taking place May 21–23 in Sea...

11 hours ago

Announcing Data API builder General Availability for Azure Cosmos DB

Great news for developers out there! The Data API Builder for Azure Cosmos DB is now officially available, eliminating the need for writing co...

1 day ago

Organizing rule collections and rule collection groups in Azure Firewall Policy

Firewall Policy is the recommended method to manage Azure Firewall security and operational configurations. When using Firewall Policy, any ru...

1 day ago

Get Started with Azure AI Services | Open AI and Deployment Models

Table of Contents   Overview - Azure AI Services Kind of Azure AI Services Responsible AI Services Limited Access Features Cognitive Acc...

1 day ago

Using Sempy to Authenticate to Fabric/Power BI APIs using Service Principal and Azure Key Vault

In this blog post, the author demonstrates how to use Azure Key Vault and Azure identity to authenticate securely when working with Fabric Not...

2 days ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy