Generally Available: Trusted Launch as Default
Share
Services
Trusted Launch as Default (TLaD) is now generally available for new Azure Gen2 virtual machines and virtual machine scale sets. TLaD automatically enables Secure Boot and vTPM for supported deployments, helping customers establish a stronger security baseline for workloads at no additional cost.
New Gen2 VMs deployed through Azure Portal, Azure CLI, and Azure PowerShell automatically use Trusted Launch by default. Customers deploying through ARM templates, Bicep, Terraform, and Azure SDKs can extend the same experience with a one-time subscription registration. Existing VMs remain unchanged, and any explicitly configured security settings continue to be honored.
Trusted Launch is available on supported x64 and Arm64 Gen2 VM sizes across Azure public, Azure Government, and Azure China regions.
[Learn more](https://techcommunity.microsoft.com/blog/microsoft-security-blog/secure-by-default-trusted-launch-as-default-is-now-generally-available/4541672).