Skip to content

Commit 0edb056

Browse files
authored
Update trusted-launch.md
1 parent cecd4e7 commit 0edb056

File tree

1 file changed

+17
-9
lines changed

1 file changed

+17
-9
lines changed

articles/virtual-machines/trusted-launch.md

Lines changed: 17 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ ms.custom: template-concept; references_regions
1313

1414
# Trusted launch for Azure virtual machines
1515

16-
**Applies to:** :heavy_check_mark: Linux VMs :heavy_check_mark: Windows VMs :heavy_check_mark: Flexible scale sets
16+
**Applies to:** :heavy_check_mark: Linux VMs :heavy_check_mark: Windows VMs :heavy_check_mark: Uniform scale sets :heavy_check_mark: Flexible scale sets
1717

1818
Azure offers trusted launch as a seamless way to improve the security of [generation 2](generation-2.md) VMs. Trusted launch protects against advanced and persistent attack techniques. Trusted launch is composed of several, coordinated infrastructure technologies that can be enabled independently. Each technology provides another layer of defense against sophisticated threats.
1919

@@ -37,20 +37,28 @@ Azure offers trusted launch as a seamless way to improve the security of [genera
3737
- DCsv2-series
3838
- Dv4-series, Dsv4-series, Dsv3-series, Dsv2-series
3939
- Ddv4-series, Ddsv4-series
40-
- Fsv2-series
40+
- Dv5-series, Dsv5-series
41+
- Ddv5-series, Ddsv5-series
42+
- Dasv5-series, Dadsv5-series
43+
- Ev5-series, Esv5-series
44+
- Edv5-series, Edsv5-series
45+
- Easv5-series, Eadsv5-series
46+
- Ebsv5-series, Ebdsv5-series
4147
- Eav4-series, Easv4-series
4248
- Ev4-series, Esv4-series, Esv3-series
4349
- Edv4-series, Edsv4-series
50+
- Fsv2-series
4451
- Lsv2-series
4552

4653
**OS support**:
47-
- Redhat Enterprise Linux 8.3, 8.5
48-
- SUSE 15 SP2
49-
- Ubuntu 20.04 LTS
50-
- Ubuntu 18.04 LTS
54+
- Redhat Enterprise Linux 8.3, 8.4, 8.5 LVM
55+
- SUSE Enterprise Linux 15 SP3
56+
- Ubuntu Server 22.04 LTS
57+
- Ubuntu Server 20.04 LTS
58+
- Ubuntu Server 18.04 LTS
5159
- Debian 11
52-
- CentOS 8.4
53-
- Oracle Linux 8.3
60+
- CentOS 8.3, 8.4
61+
- Oracle Linux 8.3 LVM
5462
- CBL-Mariner
5563
- Windows Server 2022
5664
- Windows Server 2019
@@ -102,7 +110,7 @@ Trusted launch is integrated with Azure Defender for Cloud to ensure your VMs ar
102110
- **Recommendation to enable Secure Boot** - This Recommendation only applies for VMs that support trusted launch. Azure Defender for Cloud will identify VMs that can enable Secure Boot, but have it disabled. It will issue a low severity recommendation to enable it.
103111
- **Recommendation to enable vTPM** - If your VM has vTPM enabled, Azure Defender for Cloud can use it to perform Guest Attestation and identify advanced threat patterns. If Azure Defender for Cloud identifies VMs that support trusted launch and have vTPM disabled, it will issue a low severity recommendation to enable it.
104112
- **Recommendation to install guest attestation extension** - If your VM has secure boot and vTPM enabled but it doesn't have the guest attestation extension installed, Azure Defender for Cloud will issue a low severity recommendation to install the guest attestation extension on it. This extension allows Azure Defender for Cloud to proactively attest and monitor the boot integrity of your VMs. Boot integrity is attested via remote attestation.
105-
- **Attestation health assessment** - If your VM has vTPM enabled and attestation extension installed, Azure Defender for Cloud can remotely validate that your VM booted in a healthy way. This is known as remote attestation. Azure Defender for Cloud issues an assessment, indicating the status of remote attestation.
113+
- **Attestation health assessment or Boot Integrity Monitoring** - If your VM has Secure Boot and vTPM enabled and attestation extension installed, Azure Defender for Cloud can remotely validate that your VM booted in a healthy way. This is known as boot integrity monitoring. Azure Defender for Cloud issues an assessment, indicating the status of remote attestation. Currently boot integrity monitoring is supported for both Windows and Linux singe virtual machines and uniform scale sets.
106114

107115

108116
## Microsoft Defender for Cloud integration

0 commit comments

Comments
 (0)