---
title: Ubuntu confidential VMs with Intel® TDX are now in public preview on Azure
description: Discover the future of cloud security with Ubuntu Confidential VMs featuring
  Intel TDX now available on Azure. Explore hardware-rooted isolation and encryption
  for enhanced confidentiality and integrity in your workloads. Try the public preview
  today and shape the next level of secure cloud computing
url: https://canonical.com/blog/ubuntu-confidential-vms-intel-tdx-azure-public-preview?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi "More about Ijlal Loutfi")

12 December 2023

# Ubuntu confidential VMs with Intel® TDX are now in public preview on Azure

[confidential computing](https://canonical.com/blog/tag/confidential-computing)
[confidential VM](https://canonical.com/blog/tag/confidential-vm)

---

Share the article

The Canonical confidential computing team is excited to unveil the public preview of Ubuntu Confidential VMs with  Intel® [Trust Domain Extensions](https://www.intel.com/content/www/us/en/developer/articles/technical/intel-trust-domain-extensions.html#inpage-nav-2) (Intel TDX) on Microsoft Azure, as part of  the DCesv5 and ECesv5-series VMs. These VMs leverage the cutting-edge capabilities of 4th Gen Intel Xeon Scalable processors equipped with Intel TDX, and they are ready for you to explore right now. This marks a significant achievement in Ubuntu’s mission to drive the future of confidential public clouds.

# Confidential computing threat model

[Confidential computing](https://canonical.com/blog/what-is-confidential-computing-a-high-level-explanation-for-cisos) aims to bring about a fundamental shift in the traditional threat model of public clouds. Traditionally,  any vulnerability within the millions of lines of code in the cloud’s privileged system software (OS, hypervisor, firmware) would systematically compromise the confidentiality and integrity of your running code and data. The same could be said for any undue access to your VM and/or its platform by a malicious cloud administrator.

Ubuntu Confidential VMs (CVMs) are here to give you back control over the security guarantees of your VMs. They do this by allowing you to run your workload within a logically isolated hardware-rooted execution environment.

# Intel Trust Domain Extensions

Intel® TDX  carves out a portion of system memory which is encrypted at run-time by a new AES-128 encryption engine, and by adding new access control checks that mediate access to this memory, and prevent external access to it even from the cloud’s privileged system software.

# Ubuntu confidential VMs

With this launch, Canonical Ubuntu Server 22.04 LTS also supports Full Disk Encryption. It also offers an extensive range of remote attestation solutions. These CVMs seamlessly integrate Microsoft Azure Attestation and incorporate Intel Trust Authority, catering to enterprises seeking operator-independent attestation.

In parallel, Microsoft Azure has also enriched Ubuntu CVMs with important integrity features, including boot-time attestation and confidential disk encryption with enterprise key management options for PMK (platform-managed key) and CMK (customer-managed key) using Managed HSM with FIPS 140-2 Level 3 validation.

Last but not the least, Ubuntu 22.04 confidential VMs also support ephemeral vTPMs and OS disks, a new feature where disks can be stored on the VM’s OS cache disk or the VM’s temp/resource disk, without needing to be saved to any remote Azure Storage, and where  vTPMs  generate fresh cryptographic material each time the VM boots up. This allows organisations to start building remote attestation protocols with reduced dependency on the underlying cloud infrastructure.

# **Try Ubuntu confidential VMs today**

Intel TDX Ubuntu Confidential VMs on Azure is a key step towards building a strong foundation for a [zero-trust security strategy](https://canonical.com/blog/build-foundation-zero-trust-strategy-ubuntu-confidential-computing) in the cloud. Try Ubuntu Confidential VMs on Azure today and experience the future of cloud security. We’re excited to hear your feedback.

# Other resources

* [Contact us](https://ubuntu.com/confidential-computing#get-in-touch)
* [DCesv5 and DCedsv5-series confidential VMs specifications](https://learn.microsoft.com/en-us/azure/virtual-machines/dcesv5-dcedsv5-series)
* [ECesv5 and ECedsv5-series confidential VMs specifications](https://learn.microsoft.com/en-us/azure/virtual-machines/ecesv5-ecedsv5-series)
* [Watch our webinar to learn more about confidential computing](https://www.brighttalk.com/webcast/6793/543562)
* [Read our blog post: “What is confidential computing? A high-level explanation for CISOs”](https://canonical.com/blog/what-is-confidential-computing-a-high-level-explanation-for-cisos)
* [Read our blog post:“Confidential computing in public clouds: isolation and remote attestation explained](https://canonical.com/blog/confidential-computing-in-public-clouds-isolation-and-remote-attestation-explained)”

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Sovereign clouds: enhanced data security with confidential computing](https://canonical.com/blog/sovereign-cloud-confidential-computing)

Increasingly, enterprises are interested in improving their level of control over their data, achieving digital sovereignty, and even building their own sovereign cloud....

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi)

6 March 2026

[### Join us for Microsoft Ignite](https://canonical.com/blog/join-us-for-microsoft-ignite)

The Canonical team is gearing up for the next big gathering at Microsoft Ignite 2024, which will take place from November 18 – 22, 2024. Get ready to dive deep into the latest...

[Yash Aggarwal](https://canonical.com/blog/author/yash-aggarwal)

4 November 2024

[### Deploy confidential computing with Intel® TDX and Ubuntu 24.04 today](https://canonical.com/blog/deploy-confidential-computing-intel-tdx-ubuntu-2404)

Discover how to deploy confidential computing with Intel® Trust Domain Extensions (Intel® TDX) on Ubuntu 24.04 LTS. Enhance your data security with simplified VM isolation,...

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi)

8 July 2024

[### Ubuntu Server: a platform made for enterprise scale](https://canonical.com/blog/ubuntu-server-a-platform-made-for-enterprise-scale)

A platform is an environment that allows software to run smoothly across the infrastructure, runtime, and application layers. The key word there is “smoothly”: a good platform...

[Rhys Knipe](https://canonical.com/blog/author/rhysknipe)

7 July 2026
