Skip to content

Commit d49ec86

Browse files
Merge pull request #313934 from suzuber/article-refresh-lines-71-85
Azure refresh sheet lines 71-85
2 parents e541869 + a8d626d commit d49ec86

1 file changed

Lines changed: 10 additions & 10 deletions

File tree

articles/azure-vmware/configure-virtual-trusted-platform-module.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@ title: Trusted Launch for Azure VMware Solution
33
description: Trusted Launch overview and Learn how to configure Virtual Trusted Platform Module (vTPM) on Virtual Machines.
44
ms.topic: how-to
55
ms.service: azure-vmware
6-
ms.date: 12/11/2024
6+
ms.date: 03/30/2026
77
ms.custom: engagement-fy25
88
# Customer intent: As an IT admin managing virtual machines in a cloud-based environment, I want to configure Virtual Trusted Platform Module (vTPM) on my VMs, so that I can enhance their security and ensure a trusted boot process.
99
---
1010

1111
# Trusted Launch for Azure VMware Solution
1212

13-
In this article, you will learn about Trusted Launch and how to configure Virtual Trusted Platform Module (vTPM) on Virtual Machines in Azure VMware Solution. Trusted Launch is a comprehensive security solution that encompasses three key components: Secure Boot, Virtual Trusted Platform Module (vTPM), and Virtualization-based security (VBS). Each of these components plays a vital role in fortifying the security posture of VMs.
13+
In this article, learn about Trusted Launch and how to configure Virtual Trusted Platform Module (vTPM) on Virtual Machines in Azure VMware Solution. Trusted Launch is a comprehensive security solution that encompasses three key components: Secure Boot, Virtual Trusted Platform Module (vTPM), and Virtualization-based security (VBS). Each of these components plays a vital role in fortifying the security posture of VMs.
1414

1515
:::image type="content" source="./media/trusted-launch.png" alt-text="Diagram showing the three pillars of trusted launch, Secure Boot, Virtual Trusted Platform Module, and Virtualization-based Security." border="false" lightbox="./media/trusted-launch.png":::
1616

@@ -26,15 +26,15 @@ In this article, you will learn about Trusted Launch and how to configure Virtua
2626

2727
## Secure Boot
2828

29-
Secure Boot is the first line of defense in Trusted Launch. It establishes a "root of trust" for VMs by ensuring that only signed operating systems and drivers are allowed to boot. This prevents the installation of malware-based rootkits and bootkits, which can compromise the security of the entire system. With Secure Boot enabled, every aspect of the boot process, from the boot loader to the kernel and kernel drivers, must be digitally signed by trusted publishers. This creates a robust shield against unauthorized modifications and ensures that the VM starts in a secure and trusted state.
29+
Secure Boot is the frontline of defense in Trusted Launch. It establishes a "root of trust" for VMs by ensuring that only signed operating systems and drivers are allowed to boot. Secure Boot prevents the installation of malware-based rootkits and bootkits, which can compromise the security of the entire system. With Secure Boot enabled, every aspect of the boot process (from the boot loader to the kernel and kernel drivers) should be digitally signed by trusted publishers. This creates a robust shield against unauthorized modifications and ensures that the VM starts in a secure and trusted state.
3030

3131
## Virtual Trusted Platform Module (vTPM)
3232

33-
The vTPM is a virtualized version of a hardware Trusted Platform Module (TPM) 2.0 device. It serves as a dedicated secure vault for storing keys, certificates, and secrets. What sets vTPM apart is its ability to operate in a secure environment outside the reach of any VM, making it tamper-resistant and highly secure. One of the key functions of vTPM is attestation. It measures the entire boot chain of a VM, including UEFI, OS, system components, and drivers, to certify that the VM booted securely. This attestation mechanism is invaluable for verifying the integrity of VMs and ensuring that they haven't been compromised.
33+
The vTPM is a virtualized version of a hardware Trusted Platform Module (TPM) 2.0 device. It serves as a dedicated secure vault for storing keys, certificates, and secrets. What sets vTPM apart is its ability to operate in a secure environment outside the reach of any VM, making it tamper-resistant and highly secure. One of the key functions of vTPM is attestation. It measures the entire boot chain of a VM, including Unified Extensible Firmware Interface (UEFI), OS, system components, and drivers to certify that the VM booted securely. The attestation mechanism is invaluable for verifying the integrity of VMs and ensuring that they aren't compromised.
3434

3535
## Virtualization-based Security (VBS)
3636

37-
Virtualization-based Security (VBS) is the final piece of the Trusted Launch puzzle. It leverages the hypervisor to create isolated, secure memory regions within the VM. VBS uses virtualization to enhance system security by creating an isolated, hypervisor-restricted, specialized subsystem. It provides protection against unauthorized access of credential, prevents malware from running on windows system and ensures only trusted code runs from bootloader onwards.
37+
Virtualization-based Security (VBS) is the final piece of the Trusted Launch puzzle. It uses the hypervisor to create isolated, secure memory regions within the VM. VBS uses virtualization to enhance system security by creating an isolated, hypervisor-restricted, specialized subsystem. It provides protection against unauthorized access of credential, prevents malware from running on windows system and ensures only trusted code runs from bootloader onwards.
3838

3939

4040
## Configure Virtual Trusted Platform Module (vTPM) on Virtual Machines with Azure VMware Solution
@@ -52,21 +52,21 @@ Before configuring vTPM on a VM in Azure VMware Solution, ensure the following p
5252
- Guest OS support: Linux, Windows Server 2008 and later, Windows 7 and later.
5353

5454
>[!IMPORTANT]
55-
>Customers do not need to configure a key provider to use vTPM with Azure VMware Solution. Azure VMware Solution already provides and manages key providers for each environment.
55+
>Customers don't need to configure a key provider to use vTPM with Azure VMware Solution. Azure VMware Solution already provides and manages key providers for each environment.
5656
5757
### How to Configure vTPM
5858

59-
To configure vTPM on a VM in Azure VMware Solution, follow these steps:
59+
To configure vTPM on a VM in Azure VMware Solution, use the following steps:
6060

6161
1. Connect to vCenter Server using the vSphere Client.
6262

63-
2. In the inventory, right-click the virtual machine you want to modify and select "Edit Settings".
63+
2. In the inventory, right-click the virtual machine you want to modify and select **Edit Settings**.
6464

6565
:::image type="content" source="./media/enable-virtual-trusted-platform-module-on-virtual-machine-highres.png" alt-text="Diagram showing how to enable vTPM on a virtual machine in Azure VMware Solution." border="false" lightbox="./media/enable-virtual-trusted-platform-module-on-virtual-machine-highres.png":::
6666

67-
3. In the Edit Settings dialog box, click "Add New Device" and choose "Trusted Platform Module".
67+
3. In the Edit Settings dialog box, select **Add New Device** and choose **Trusted Platform Module**.
6868

69-
4. Click "OK". The virtual machine Summary tab displays the Virtual Trusted Platform Module in the VM Hardware pane.
69+
4. Select **OK**. The virtual machine Summary tab displays the Virtual Trusted Platform Module in the VM Hardware pane.
7070

7171
>[!IMPORTANT]
7272
>On VMware vSphere 7, cloning a virtual machine creates an exact replica of both the VM and the vTPM. VMware vSphere 8 introduces options to either copy or replace the TPM, allowing for better handling of different use cases.

0 commit comments

Comments
 (0)