/
vTPM Should be Enabled on Supported Virtual Machines

vTPM Should be Enabled on Supported Virtual Machines

Description:

Enable virtual TPM device on supported virtual machines to facilitate Measured Boot and other OS security features that require a TPM. Once enabled, vTPM can be used to attest boot integrity. This assessment only applies to trusted launch enabled virtual machines.

Important:
Trusted launch requires the creation of new virtual machines.
You can't enable trusted launch on existing virtual machines that were initially created without it.
Trusted launch is currently in public preview. The preview is provided without a service level agreement, and it's not recommended for production workloads. Certain features might not be supported or might have constrained capabilities. Learn more in Trusted launch for Azure virtual machines.



Remediation/Reference:

Enabling vTPM will trigger an immediate SYSTEM REBOOT. To enable it:
1. Select the VM.
2. On the VM page, navigate to the 'Configuration' tab.
3. On the 'Configuration' page, check 'vTPM'.
4. Click 'Save'.

https://docs.microsoft.com/en-us/azure/virtual-machines/trusted-launch?WT.mc_id=Portal-Microsoft_Azure_Security

Related content

Secure Boot Should be Enabled on Supported Windows Virtual Machines
Secure Boot Should be Enabled on Supported Windows Virtual Machines
More like this
Linux Virtual Machines Should Use Secure Boot
Linux Virtual Machines Should Use Secure Boot
More like this
Guest Attestation Extension Should be Installed on XYZ
Guest Attestation Extension Should be Installed on XYZ
More like this
Virtual Machines Guest Attestation Status Should be Healthy
Virtual Machines Guest Attestation Status Should be Healthy
More like this
Linux Virtual Machines Should Enforce Kernel Module Signature Validation
Linux Virtual Machines Should Enforce Kernel Module Signature Validation
More like this
Machines Should be Restarted to Apply security Configuration Updates
Machines Should be Restarted to Apply security Configuration Updates
More like this