Ensure Trusted Launch is enabled on Virtual Machines
Description
When Secure Boot and vTPM are enabled together, they provide a strong foundation for protecting your VM from boot attacks. For example, if an attacker attempts to replace the bootloader with a malicious version, Secure Boot will prevent the VM from booting. If the attacker is able to bypass Secure Boot and install a malicious bootloader, vTPM can be used to detect the intrusion and alert you.
Rationale
Secure Boot and vTPM work together to protect your VM from a variety of boot attacks, including bootkits, rootkits, and firmware rootkits. Not enabling Trusted Launch in Azure VM can lead to increased vulnerability to rootkits and boot-level malware, reduced ability to detect and prevent unauthorized changes to the boot process, and a potential compromise of system integrity and data security.
Impact
Secure Boot and vTPM are not currently supported for Azure Generation 1 VMs.
IMPORTANT: Before enabling Secure Boot and vTPM on a Generation 2 VM which does not already have both enabled, it is highly recommended to create a restore point of the VM prior to remediation.
Audit Procedure
Using Azure Portal
- Go to Virtual Machines
- For each VM, under Settings, click on Configuration on the left blade
- Under Security Type, make sure security type is not standard and if it is Trusted Launch Virtual Machines then make sure Enable Secure Boot & Enable vTPM are checked
Using Azure CLI
Run the following command to list VM names and security profile settings:
az vm list --query [*].[name,securityProfile]
For each VM, ensure that securityType is set to TrustedLaunch, uefiSettings.secureBootEnabled is set to true, and uefiSettings.vTpmEnabled is set to true.
Using Azure PowerShell
Run the following command to list VMs:
Get-AzVm
Run the following command to get the VM in a resource group with a given name:
$vm = Get-AzVm -ResourceGroupName <resource-group> -Name <vm>
Run the following command to get the security profile settings for the VM:
$vm.SecurityProfile
Ensure that SecurityType is set to TrustedLaunch.
Run the following command to get the UEFI settings for the VM:
$vm.SecurityProfile.UefiSettings
Ensure that SecureBootEnabled and VTpmEnabled are set to True.
Repeat for each VM.
Expected Result
All VMs should have securityType set to TrustedLaunch with both secureBootEnabled and vTpmEnabled set to true.
Remediation
Note: Trusted launch on existing virtual machines (VMs) is currently not supported for Azure Generation 1 VMs.
Using Azure Portal
- Go to Virtual Machines.
- For each VM, under Settings, click on Configuration on the left blade.
- Under Security Type, select 'Trusted Launch Virtual Machines'.
- Make sure Enable Secure Boot & Enable vTPM are checked.
- Click on Apply.
Using Azure CLI
Ensure that it is safe to change the state of the VM.
Run the following command to deallocate the VM:
az vm deallocate --resource-group <resource-group> --name <vm>
Run the following command to update the VM, setting security type to TrustedLaunch and enabling secure boot and vTPM:
az vm update --resource-group <resource-group> --name <vm> --enable-secure-boot true --enable-vtpm true --security-type TrustedLaunch
Run the following command to restart the VM:
az vm start --resource-group <resource-group> --name <vm>
Repeat for each VM requiring remediation.
Using Azure PowerShell
Ensure it is safe to change the state of the VM.
Run the following command to stop the VM:
Stop-AzVm -ResourceGroupName <resource-group> -Name <vm> -Force
Run the following command to get the VM in a resource group with a given name:
$vm = Get-AzVM -ResourceGroupName <resource-group> -Name <vm>
Run the following command to update the VM, setting security type to TrustedLaunch and enabling secure boot and vTPM:
Update-AzVm -ResourceGroupName <resource-group> -VM $vm -EnableSecureBoot 1 -EnableVtpm 1 -SecurityType TrustedLaunch
Run the following command to start the VM:
Start-AzVm -ResourceGroupName <resource-group> -Name <vm>
Repeat for each VM requiring remediation.
Default Value
On Azure Generation 2 VMs, vTPM is enabled by default. Secure Boot is not enabled by default.
References
- https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm?tabs=portal
- https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm?tabs=portal#enable-trusted-launch-on-existing-vm
- https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch#secure-boot
- https://learn.microsoft.com/en-us/cli/azure/vm
- https://learn.microsoft.com/en-us/powershell/module/az.compute/get-azvm
- https://learn.microsoft.com/en-us/powershell/module/az.compute/stop-azvm
- https://learn.microsoft.com/en-us/powershell/module/az.compute/update-azvm
- https://learn.microsoft.com/en-us/powershell/module/az.compute/start-azvm
Profile
Level 1 | Automated