---
title: Let’s get confidential!   Canonical Ubuntu Confidential VMs are now generally
  available on Microsoft Azure
description: Canonical Ubuntu confidential VMs protect your data and code at run-time
  from the cloud provider itself, its staff, and other VMs.
url: https://canonical.com/blog/lets-get-confidential-canonical-ubuntu-confidential-vms-are-now-generally-available-on-microsoft-azure?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi "More about Ijlal Loutfi")

28 July 2022

# Let’s get confidential! Canonical Ubuntu Confidential VMs are now generally available on Microsoft Azure

[confidential computing](https://canonical.com/blog/tag/confidential-computing)
[confidential VM](https://canonical.com/blog/tag/confidential-vm)
[Trusted Execution Environment](https://canonical.com/blog/tag/trusted-execution-environment)
[Trusted execution environments](https://canonical.com/blog/tag/trusted-execution-environments)

---

Share the article

On behalf of all Canonical teams, I am happy to announce the general availability of Ubuntu **C**onfidential **VMs** (CVMs) on Microsoft Azure! They  are part of the [Microsoft Azure DCasv5/ECasv5 series](https://docs.microsoft.com/en-us/azure/confidential-computing/confidential-vm-overview), and only take a few [clicks to enable and use](https://docs.microsoft.com/en-us/azure/confidential-computing/quick-create-confidential-vm-portal-amd). [Ubuntu 20.04](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/canonical.0001-com-ubuntu-server-focal?tab=Overview) is the first and only Linux distribution to support Confidential VMs on Azure.

## What are Ubuntu CVMs?

Ubuntu CVMs use the latest security extensions of the third generation of [AMD CPUs, Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP).](https://www.amd.com/en/processors/amd-secure-encrypted-virtualization) As such, they bring about a fundamental shift in the traditional threat model of public clouds. Traditionally,  any vulnerability within the millions of lines of code in the cloud’s privileged system software (OS, hypervisor, firmware) would systematically compromise the confidentiality and integrity of your running code and data. The same could be said for any undue access to your VM and/or its platform by a malicious cloud administrator.

Ubuntu CVMs are here to give you back control over the security guarantees of your VMs. They do this by allowing you to run your workload within a logically isolated hardware-rooted execution environment.  Your trusted computing base is dramatically reduced to your application and the platform’s underlying hardware CPU, and nothing else. In other words, a compromised host OS or an angry cloud administrator can no longer access your data nor alter your code’s execution.

*Photo by [Fidel Fernando](https://unsplash.com/@fifernando) on* [*Unsplash*](https://unsplash.com/?utm_source=your_app_name&utm_medium=referral)

## How do Ubuntu confidential VMs work?

Ubuntu CVMs achieve such strong security guarantees by securing your VMs throughout their entire lifecycle:

**1.At run-time**
Using AMD SEV-SNP, your VM’s code and data are encrypted when they are being operated on in the system memory. The encryption leverages the newest AES-128 hardware encryption engine embedded in the CPU’s memory controller. The encryption key is further protected and managed by the AMD Secure Processor.

**2. At rest**
Your entire workload is encrypted using Ubuntu-enhanced full disk encryption capabilities. The encryption key is itself stored encrypted in your VM’s virtual disk. It’s then  bound to the virtual TPM (vTPM) associated with your instance. Finally, the vTPM is itself part of the guest VM address space, and enjoys the same run-time security guarantees provided by the AMD SEV-SNP extensions to the entire VM instance.

**3. At boot time**
Before booting the VM, the platform provides a hardware-rooted signed attestation which can be used to verify the OS, firmware and platform boot measurements.

## Part of Canonical’s security commitment

With Ubuntu CVMs, Canonical continues its strong commitment to [security](https://ubuntu.com/security). This is yet another reason for which developers, end-users and enterprises across the world continue to choose Ubuntu on all major public clouds. With Azure CVM, Ubuntu customers can continue using its [extended security maintenance of 10 years](https://ubuntu.com/security/esm), [certified and hardened images](https://ubuntu.com/security/certifications) and [kernel livepatch capabilities,](https://ubuntu.com/security/livepatch)  while enjoying the Ubuntu user experience they have come to love and expect.

## Stay tuned for more news on confidential computing

Azure Confidential VMs only mark the beginning of Ubuntu’s confidential computing capabilities across various public clouds and compute classes. We look forward to sharing more news about our expanding portfolio and learning about the novel ways you are leveraging confidential computing.

### More resources

* [Contact us](https://ubuntu.com/confidential-computing#get-in-touch)
* [Watch our webinar to learn more about confidential computing](https://www.brighttalk.com/webcast/6793/543562)
* [Take a deep dive into how we enabled CVMs on Azure](https://ubuntu.com/blog/how-we-designed-ubuntu-pro-for-confidential-computing-on-azure)
* [Start creating and using Ubuntu CVMs on Azure](https://docs.microsoft.com/en-us/azure/confidential-computing/quick-create-confidential-vm-portal-amd)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Sovereign clouds: enhanced data security with confidential computing](https://canonical.com/blog/sovereign-cloud-confidential-computing)

Increasingly, enterprises are interested in improving their level of control over their data, achieving digital sovereignty, and even building their own sovereign cloud....

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi)

6 March 2026

[### Join us for Microsoft Ignite](https://canonical.com/blog/join-us-for-microsoft-ignite)

The Canonical team is gearing up for the next big gathering at Microsoft Ignite 2024, which will take place from November 18 – 22, 2024. Get ready to dive deep into the latest...

[Yash Aggarwal](https://canonical.com/blog/author/yash-aggarwal)

4 November 2024

[### Deploy confidential computing with Intel® TDX and Ubuntu 24.04 today](https://canonical.com/blog/deploy-confidential-computing-intel-tdx-ubuntu-2404)

Discover how to deploy confidential computing with Intel® Trust Domain Extensions (Intel® TDX) on Ubuntu 24.04 LTS. Enhance your data security with simplified VM isolation,...

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi)

8 July 2024

[### Ubuntu Server: a platform made for enterprise scale](https://canonical.com/blog/ubuntu-server-a-platform-made-for-enterprise-scale)

A platform is an environment that allows software to run smoothly across the infrastructure, runtime, and application layers. The key word there is “smoothly”: a good platform...

[Rhys Knipe](https://canonical.com/blog/author/rhysknipe)

7 July 2026
