Trusted launch and confidential computing
As well as securing the software, network, and OS layer, the IT admin also needs to think about the hardware layer. Luckily, Microsoft provides several options to achieve this.
Trusted launch
Trusted launch is offered on Gen 2 Azure virtual machines. It offers several security enhancements that can be enabled separately. When starting the process of creating a new Azure virtual machine in the portal, the trusted launch is automatically selected. However, the IT admin can select which options to activate. By default, Enable secure boot and Enable vTPM are selected, as shown in the following figure.
Figure 10.50 – Configuring trusted launch
Let’s discuss what each option does:
- Enable secure boot: This feature will protect the virtual machine from rootkits that overwrite the firmware, boot kits that replace the OS bootloader, kernel rootkits that replace a piece of the OS kernel, and driver...