8.11 Ensure Trusted Launch is enabled on Virtual Machines

Information

When Secure Boot and vTPM are enabled together, they provide a strong foundation for protecting your VM from boot attacks. For example, if an attacker attempts to replace the bootloader with a malicious version, Secure Boot will prevent the VM from booting. If the attacker is able to bypass Secure Boot and install a malicious bootloader, vTPM can be used to detect the intrusion and alert you.

Rationale:

Secure Boot and vTPM work together to protect your VM from a variety of boot attacks, including bootkits, rootkits, and firmware rootkits. Not enabling Trusted Launch in Azure VM can lead to increased vulnerability to rootkits and boot-level malware, reduced ability to detect and prevent unauthorized changes to the boot process, and a potential compromise of system integrity and data security.

Impact:

Secure Boot and vTPM are not currently supported for Azure Generation 1 VMs.

IMPORTANT: Before enabling Secure Boot and vTPM on a Generation 2 VM which does not already have both enabled, it is highly recommended to create a restore point of the VM prior to remediation.

Solution

Remediate from Azure Portal

Go to Virtual Machines.

For each VM, under Settings, click on Configuration on the left blade.

Under Security Type, select 'Trusted Launch Virtual Machines'.

Make sure Enable Secure Boot & Enable vTPM are checked.

Click on Apply.

Note: Trusted launch on existing virtual machines (VMs) is currently not supported for Azure Generation 1 VMs

Default Value:

On Azure Generation 2 VMs, vTPM is enabled by default. Secure Boot is not enabled by default.

See Also

https://workbench.cisecurity.org/benchmarks/16820

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: microsoft_azure

Control ID: a3f6aef71e39bd2bf39bf220407ea47414feb4f7b4226176dad18a1bc766b748