Maintained with ☕️ by
IcePanel logo

Generally Available: Custom Secure Boot UEFI Keys for Azure Trusted Launch VM

Share

Services

Trusted Launch VM now supports customizing secure boot UEFI keys. One or more of the secure boot keys and/or databases (PK, KEK, DB, or DBX) can be fully replaced or updated. This allows additional flexibility to further secure workloads using Trusted Launch virtual machines in Azure. Trusted Launch VM improves security posture of workloads in Azure VM. * Protect against persistent boot/kernel malware (improved security posture) * Boot to a defined and trusted state * Meet industry/NIST security best practices/standards + Microsoft security benchmark For more information about the capabilities available, please visit [Trusted Launch VM](https://aka.ms/TrustedLaunch), [Secure boot UEFI keys](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-secure-boot-custom-uefi) documentation pages.