Access to this page requires authorization. You can try signing in or changing directories .
Access to this page requires authorization. You can try changing directories .
Azure confidential VMs offer strong security and confidentiality for tenants. They create a hardware-enforced boundary between your application and the virtualization stack. You can use them for cloud migrations without modifying your code, and the platform ensures your VM’s state remains protected.
Protection levels differ based on your configuration and preferences. For example, Microsoft can own or manage encryption keys for increased convenience at no additional cost.
Confidential VMs Benefits
Robust hardware-based isolation between virtual machines, hypervisor, and host management code.
Customizable attestation policies to ensure the host's compliance before deployment.
Cloud-based Confidential OS disk encryption before the first boot.
VM encryption keys that the platform or the customer (optionally) owns and manages.
Secure key release with cryptographic binding between the platform's successful attestation and the VM's encryption keys.
Dedicated virtual Trusted Platform Module (TPM) instance for attestation and protection of keys and secrets in the virtual machine.
Secure boot capability similar to Trusted launch for Azure VMs
Confidential OS disk encryption
Azure confidential VMs offer a new and enhanced disk encryption scheme. This scheme protects all critical partitions of the disk. It also binds disk encryption keys to the virtual machine's TPM and makes the protected disk content accessible only to the VM. These encryption keys can securely bypass Azure components, including the hypervisor and host operating system. To minimize the attack potential, a dedicated and separate cloud service also encrypts the disk during the initial creation of the VM.
If the compute platform is missing critical settings for your VM's isolation, Azure Attestation will not attest to the platform's health during boot, and will instead prevent the VM from starting. This scenario happens if you haven't enabled SEV-SNP, for example.
Confidential OS disk encryption is optional, as this process can lengthen the initial VM creation time. You can choose between:
A confidential VM with Confidential OS disk encryption that uses platform-managed keys (PMK) or a customer-managed key (CMK).
A confidential VM with Confidential OS disk encryption that uses platform-managed keys (PMK) or a customer-managed key (CMK).
A confidential VM without Confidential OS disk encryption.
A confidential VM without Confidential OS disk encryption.
Confidential OS disk encryption setting can't be changed after VM deployment
For further integrity and protection, confidential VMs offer Secure Boot by default when confidential OS disk encryption is selected.
With Secure Boot, trusted publishers must sign OS boot components (including the boot loader, kernel, and kernel drivers). All compatible confidential VM images support Secure Boot.
Confidential temp disk encryption
You can also extend the protection of confidential disk encryption to the temp disk. We enable this by leveraging an in-VM symmetric key encryption technology, after the disk is attached to the CVM.
The temp disk provides fast, local, and short-term storage for applications and processes. It is intended to only store data such as page files, log files, cached data, and other types of temporary data. Temp disks on CVMs contain the page file, also known as swap file, that can contain sensitive data. Without encryption, data on these disks may be accessible to the host. After enabling this feature, data on the temp disks is no longer exposed to the host.
Encryption pricing differences
Azure confidential VMs use both the OS disk and a small encrypted virtual machine guest state (VMGS) disk of several megabytes. The VMGS disk contains the security state of the VM's components. Some components include the vTPM and UEFI bootloader. The small VMGS disk might incur a monthly storage cost.
From March 30 2026, encrypted OS disks will incur higher costs. For more information, see the pricing guide for managed disks .
Azure confidential VMs boot only after successful attestation of the platform's critical components and security settings. The attestation report includes:
A signed attestation report
Platform boot settings
Platform firmware measurements
You can initialize an attestation request inside of a confidential VM to verify that your confidential VMs are running a hardware instance with either AMD SEV-SNP, or Intel TDX enabled processors. For more information, see Azure confidential VM guest attestation .
Azure confidential VMs feature a virtual TPM (vTPM) for Azure VMs. The vTPM is a virtualized version of a hardware TPM, and complies with the TPM 2.0 spec. You can use a vTPM as a dedicated, secure vault for keys and measurements. Confidential VMs have their own dedicated vTPM instance, which runs in a secure environment outside the reach of any VM.
The following limitations exist for confidential VMs. For frequently asked questions, see FAQ confidential VMs .
Confidential VMs support the following VM sizes:
General Purpose without local disk: DCasv5-series, DCasv6-series DCesv6-series
General Purpose with local disk: DCadsv5-series, DCadsv6-series DCedsv6-series
Memory Optimized without local disk: ECasv5-series, ECasv6-series ECesv6-series
Memory Optimized with local disk: ECadsv5-series, ECadsv6-series ECedsv6-series
NVIDIA H100 Tensor Core GPU powered NCCadsH100v5-series
OS images for confidential VMs must meet specific security requirements. These qualified images are designed to support an optional confidential OS disk encryption and ensure isolation from the underlying cloud infrastructure. Meeting these requirements helps protect sensitive data and maintain system integrity.
Confidential VMs support the following OS options:
Confidential VMs run on specialized hardware available in specific VM regions .
Pricing depends on your confidential VM size. For more information, see the Pricing Calculator .
Azure Backup support for Confidential VMs is currently in public preview Documentation
Confidential VMs don't support :
Limited Azure Compute Gallery support
Accelerated Networking
Screenshots under boot diagnostics
Confidential disk encryption is only supported for disks that are smaller than 128 GB. For larger disks, it is recommended to opt for Premium SSDs, particularly for disks exceeding 32 GB.
Auto keyrotation is not supported, only offline key rotation is supported.
Deploy a confidential VM from the Azure portal
For more information see our Confidential VM FAQ .
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?
Last updated on 2026-02-05
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
