Azure Goes Secure by Default with Trusted Launch Activation
Microsoft has made Trusted Launch the default security feature for new Azure Gen2 virtual machines and virtual machine scale sets. This change automatically applies key security protections, including Secure Boot and vTPM, to new deployments without adding cost or administrative overhead.
Trusted Launch is a security capability that helps protect systems from sophisticated threats targeting the boot process and operating system. It combines technologies such as Secure Boot, virtual Trusted Platform Module (vTPM), and continuous boot integrity checks to create a trusted foundation for workloads and detect unauthorized changes before they can compromise a virtual machine.
Microsoft notes that existing virtual machines are unaffected by this change, and organizations can opt out when necessary. A one-time subscription registration is required for ARM templates, Bicep, Terraform, and Azure SDKs to enable Trusted Launch as the default setting for new deployments.