You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/backup/backup-support-matrix-iaas.md
+5-4Lines changed: 5 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -53,7 +53,7 @@ Multiple Backups Per Day | Supported (in preview), using *Enhanced policy* (
53
53
54
54
## Operating system support (Windows)
55
55
56
-
The following table summarizes the supported operating systems when backing up Windows Azure VMs.
56
+
The following table summarizes the supported operating systems when backing up Azure VMs running Windows.
57
57
58
58
**Scenario** | **OS support**
59
59
--- | ---
@@ -164,7 +164,8 @@ Backup of Azure VMs with locks | Unsupported for unmanaged VMs. <br><br> Support
164
164
Windows Storage Spaces configuration of standalone Azure VMs | Supported
165
165
[Azure Virtual Machine Scale Sets](../virtual-machine-scale-sets/virtual-machine-scale-sets-orchestration-modes.md#scale-sets-with-flexible-orchestration) | Supported for flexible orchestration model to back up and restore Single Azure VM.
166
166
Restore with Managed identities | Yes, supported for managed Azure VMs, and not supported for classic and unmanaged Azure VMs. <br><br> Cross Region Restore isn't supported with managed identities. <br><br> Currently, this is available in all Azure public and national cloud regions. <br><br> [Learn more](backup-azure-arm-restore-vms.md#restore-vms-with-managed-identities).
167
-
<aname="tvm-backup">Trusted Launch VM</a> | Backup supported. <br><br> Backup of Trusted Launch VM is supported through [Enhanced policy](backup-azure-vms-enhanced-policy.md). You can enable backup through [Recovery Services vault](./backup-azure-arm-vms-prepare.md), [VM Manage blade](./backup-during-vm-creation.md#start-a-backup-after-creating-the-vm), and [Create VM blade](backup-during-vm-creation.md#create-a-vm-with-backup-configured). <br><br> **Feature details** <br> <ul><li> Backup is supported in all regions where Trusted Launch VM is available. </li><li> Configurations of Backup, Alerts, and Monitoring for Trusted Launch VM are currently not supported through Backup center. </li><li> Migration of an existing [Generation 2](../virtual-machines/generation-2.md) VM (protected with Azure Backup) to Trusted Launch VM is currently not supported. Learn about how to [create a Trusted Launch VM](../virtual-machines/trusted-launch-portal.md?tabs=portal#deploy-a-trusted-vm). </li></ul>
167
+
<a name="tvm-backup">Trusted Launch VM</a> | Backup supported. <br><br> Backup of Trusted Launch VM is supported through [Enhanced policy](backup-azure-vms-enhanced-policy.md). You can enable backup through [Recovery Services vault](./backup-azure-arm-vms-prepare.md), [VM Manage blade](./backup-during-vm-creation.md#start-a-backup-after-creating-the-vm), and [Create VM blade](backup-during-vm-creation.md#create-a-vm-with-backup-configured). <br><br> **Feature details** <br> <ul><li> Backup is supported in all regions where Trusted Launch VM is available. </li><li> Configurations of Backup, Alerts, and Monitoring for Trusted Launch VM are currently not supported through Backup center. </li><li> Migration of an existing [Generation 2](../virtual-machines/generation-2.md) VM (protected with Azure Backup) to Trusted Launch VM is currently not supported. Learn about how to [create a Trusted Launch VM](../virtual-machines/trusted-launch-portal.md?tabs=portal#deploy-a-trusted-launch-vm). </li></ul>
168
+
168
169
169
170
## VM storage support
170
171
@@ -222,7 +223,7 @@ Network traffic to Azure:
222
223
Data security:
223
224
224
225
- When backing up Azure VMs, you need to set up encryption *within* the virtual machine.
225
-
- Azure Backup supports Azure Disk Encryption, which uses BitLocker on Windows virtual machines and us**dm-crypt** on Linux virtual machines.
226
+
- Azure Backup supports Azure Disk Encryption, which uses BitLocker on virtual machines running Windows and uses**dm-crypt** on Linux virtual machines.
226
227
- On the back end, Azure Backup uses [Azure Storage Service encryption](../storage/common/storage-service-encryption.md), which protects data at rest.
Copy file name to clipboardExpand all lines: articles/virtual-machines/trusted-launch-portal.md
+166-5Lines changed: 166 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,19 +1,19 @@
1
1
---
2
2
title: Deploy a trusted launch VM
3
3
description: Deploy a VM that uses trusted launch.
4
-
author: cynthn
5
-
ms.author: cynthn
4
+
author: lakmeedee
5
+
ms.author: dejv
6
6
ms.reviewer: cynthn
7
7
ms.service: virtual-machines
8
8
ms.subservice: trusted-launch
9
9
ms.topic: how-to
10
-
ms.date: 12/07/2021
10
+
ms.date: 03/22/2022
11
11
ms.custom: template-how-to, devx-track-azurecli
12
12
---
13
13
14
14
# Deploy a VM with trusted launch enabled
15
15
16
-
**Applies to:**:heavy_check_mark: Linux VMs :heavy_check_mark: Windows VMs :heavy_check_mark: Flexible scale sets
16
+
**Applies to:**:heavy_check_mark: Linux VMs :heavy_check_mark: Windows VMs :heavy_check_mark: Flexible scale sets:heavy_check_mark: Uniform scale sets
17
17
18
18
[Trusted launch](trusted-launch.md) is a way to improve the security of [generation 2](generation-2.md) VMs. Trusted launch protects against advanced and persistent attack techniques by combining infrastructure technologies like vTPM and secure boot.
- Configure machines to automatically install the Azure Monitor and Azure Security agents on virtual machines
28
28
29
29
30
-
## Deploy a trusted VM
30
+
## Deploy a trusted launch VM
31
31
Create a virtual machine with trusted launch enabled. Choose an option below:
32
32
33
33
### [Portal](#tab/portal)
@@ -154,6 +154,167 @@ You can deploy trusted launch VMs using a quickstart template:
154
154
155
155
---
156
156
157
+
## Deploy a trusted launch VM from an Azure Compute Gallery image
158
+
159
+
### [Portal](#tab/portal2)
160
+
161
+
1. Sign in to the Azure [portal](https://portal.azure.com).
162
+
2. To create an Azure Compute Gallery Image from a VM, open an existing Trusted launch VM and select **Capture**.
163
+
3. In the Create an Image page that follows, allow the image to be shared to the gallery as a VM image version as Managed Images are not supported for Trusted Launch.
164
+
4. Create a new target Azure Compute Gallery or select an existing gallery.
165
+
5. Select the **Operating system state** as either **Generalized** or **Specialized**.
166
+
6. Create a new image definition by providing a name, publisher, offer and SKU details. The Security Type of the image definition is already set to 'Trusted launch'.
167
+
7. Provide a version number for the image version.
168
+
8. Modify replication options if required.
169
+
9. At the bottom of the **Create an Image** page, select **Review + Create** and when validation shows as passed, select **Create**.
170
+
10. Once the image version is created, go the image version directly. Alternatively, you can navigate to the required image version through the image definition.
171
+
11. On the **VM image version** page, select the **+ Create VM** to land on the Create a virtual machine page.
172
+
12. In the Create a virtual machine page, under **Resource group**, select **Create new** and type a name for your resource group or select an existing resource group from the dropdown.
173
+
13. Under **Instance details**, type a name for the virtual machine name and choose a region that supports [trusted launch](trusted-launch.md#limitations).
174
+
14. The image and the security type are already populated based on the selected image version. The **Secure Boot** and **vTPM** checkboxes are enabled by default.
175
+
15. Fill in the **Administrator account** information and then **Inbound port rules**.
176
+
16. At the bottom of the page, select **Review + Create**
177
+
17. On the **Create a virtual machine** page, you can see the details about the VM you are about to deploy. Once validation shows as passed, select **Create**.
178
+
179
+
### [CLI](#tab/cli2)
180
+
181
+
Make sure you are running the latest version of Azure CLI
182
+
183
+
Sign in to Azure using `az login`.
184
+
185
+
```azurecli-interactive
186
+
az login
187
+
```
188
+
189
+
Create an image definition with TrustedLaunch security type
190
+
191
+
```azurecli-interactive
192
+
az sig image-definition create --resource-group MyResourceGroup --location eastus \
For VMs created with trusted launch enabled, you can view the trusted launch configuration by visiting the **Overview** page for the VM in the portal. The **Properties** tab will show the status of Trusted Launch features:
0 commit comments