{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/",
        "slug": "dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/"
        },
        "title": "Plan Trusted Launch rollback as a one-way security transition",
        "summary": "Can an existing Azure Gen2 VM be freely toggled between Trusted Launch and Standard security?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:23+00:00",
        "modified_at": "2026-09-10T00:35:08+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 246,
        "potentially_affected": "Owners reviewing rollback for an existing Azure Gen2 VM upgraded to Trusted Launch.",
        "dse_recommendation": "Approve the one-way consequence before changing the VM back to Standard security.",
        "primary_source": {
            "name": "Enable Trusted launch on existing Gen2 VMs - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents rollback from Trusted Launch to non-Trusted-Launch Gen2 by setting securityType to Standard. It calls this a one-way operation: Trusted Launch cannot subsequently be re-enabled on that same VM. The portal does not support this rollback, and the documented API minimum is 2025-11-01. The CLI and PowerShell procedures deallocate the VM before changing its security type. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for an existing Gen2 VM&#8217;s security rollback, not as a procedure for returning a converted VM to Gen1. Check the current supported client versions and full prerequisites. Identify the application&#8217;s outage allowance and the security owner&#8217;s reason for removing the protection.</p>\n<h2>DSE recommendation</h2>\n<p>Approve the one-way consequence before changing the VM back to Standard security. Have the recovery owner preserve an appropriate known-good recovery path before the original upgrade and distinguish that recovery from an in-place security change. Document how any future requirement for Trusted Launch would be met without assuming a simple toggle on the same resource.</p>\n<h2>Verification</h2>\n<p>Rehearse the approved recovery decision on a representative test resource and inspect the resulting security profile after the supported operation. Verify boot, authorized access, and the application&#8217;s critical workflow before closing the change. Retain the deallocation window and observed state with the risk decision. Do not describe a successful return to Standard as proof that the original security setting can later be restored through the same operation.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Enable Trusted Launch on existing Gen2 VMs</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft documents rollback from Trusted Launch to non-Trusted-Launch Gen2 by setting securityType to Standard. It calls this a one-way operation: Trusted Launch cannot subsequently be re-enabled on that same VM. The portal does not support this rollback, and the documented API minimum is 2025-11-01. The CLI and PowerShell procedures deallocate the VM before changing its security type. Microsoft Learn.\nApplicability\nUse this review for an existing Gen2 VM’s security rollback, not as a procedure for returning a converted VM to Gen1. Check the current supported client versions and full prerequisites. Identify the application’s outage allowance and the security owner’s reason for removing the protection.\nDSE recommendation\nApprove the one-way consequence before changing the VM back to Standard security. Have the recovery owner preserve an appropriate known-good recovery path before the original upgrade and distinguish that recovery from an in-place security change. Document how any future requirement for Trusted Launch would be met without assuming a simple toggle on the same resource.\nVerification\nRehearse the approved recovery decision on a representative test resource and inspect the resulting security profile after the supported operation. Verify boot, authorized access, and the application’s critical workflow before closing the change. Retain the deallocation window and observed state with the risk decision. Do not describe a successful return to Standard as proof that the original security setting can later be restored through the same operation.\nOfficial references\nMicrosoft Learn: Enable Trusted Launch on existing Gen2 VMs. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft documents rollback from Trusted Launch to non-Trusted-Launch Gen2 by setting securityType to Standard. It calls this a one-way operation: Trusted Launch cannot subsequently be re-enabled on that same VM. The portal does not support this rollback, and the documented API minimum is 2025-11-01. The CLI and PowerShell procedures deallocate the VM before changing its security type. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm).\n\n## Applicability\n\nUse this review for an existing Gen2 VM’s security rollback, not as a procedure for returning a converted VM to Gen1. Check the current supported client versions and full prerequisites. Identify the application’s outage allowance and the security owner’s reason for removing the protection.\n\n## DSE recommendation\n\nApprove the one-way consequence before changing the VM back to Standard security. Have the recovery owner preserve an appropriate known-good recovery path before the original upgrade and distinguish that recovery from an in-place security change. Document how any future requirement for Trusted Launch would be met without assuming a simple toggle on the same resource.\n\n## Verification\n\nRehearse the approved recovery decision on a representative test resource and inspect the resulting security profile after the supported operation. Verify boot, authorized access, and the application’s critical workflow before closing the change. Retain the deallocation window and observed state with the risk decision. Do not describe a successful return to Standard as proof that the original security setting can later be restored through the same operation.\n\n## Official references\n\n[Microsoft Learn: Enable Trusted Launch on existing Gen2 VMs](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Plan Trusted Launch rollback as a one-way security transition",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/",
                "headline": "Plan Trusted Launch rollback as a one-way security transition",
                "description": "Can an existing Azure Gen2 VM be freely toggled between Trusted Launch and Standard security?",
                "abstract": "Can an existing Azure Gen2 VM be freely toggled between Trusted Launch and Standard security?",
                "articleBody": "Source facts\nMicrosoft documents rollback from Trusted Launch to non-Trusted-Launch Gen2 by setting securityType to Standard. It calls this a one-way operation: Trusted Launch cannot subsequently be re-enabled on that same VM. The portal does not support this rollback, and the documented API minimum is 2025-11-01. The CLI and PowerShell procedures deallocate the VM before changing its security type. Microsoft Learn.\nApplicability\nUse this review for an existing Gen2 VM’s security rollback, not as a procedure for returning a converted VM to Gen1. Check the current supported client versions and full prerequisites. Identify the application’s outage allowance and the security owner’s reason for removing the protection.\nDSE recommendation\nApprove the one-way consequence before changing the VM back to Standard security. Have the recovery owner preserve an appropriate known-good recovery path before the original upgrade and distinguish that recovery from an in-place security change. Document how any future requirement for Trusted Launch would be met without assuming a simple toggle on the same resource.\nVerification\nRehearse the approved recovery decision on a representative test resource and inspect the resulting security profile after the supported operation. Verify boot, authorized access, and the application’s critical workflow before closing the change. Retain the deallocation window and observed state with the risk decision. Do not describe a successful return to Standard as proof that the original security setting can later be restored through the same operation.\nOfficial references\nMicrosoft Learn: Enable Trusted Launch on existing Gen2 VMs. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:23+00:00",
                "dateModified": "2026-09-10T00:35:08+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Plan Trusted Launch rollback as a one-way security transition"
                },
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 246,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Enable Trusted launch on existing Gen2 VMs - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm"
                }
            }
        ]
    }
}