# Plan Trusted Launch rollback as a one-way security transition

> Can an existing Azure Gen2 VM be freely toggled between Trusted Launch and Standard security?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:23+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can an existing Azure Gen2 VM be freely toggled between Trusted Launch and Standard security?

## Potentially affected

Owners reviewing rollback for an existing Azure Gen2 VM upgraded to Trusted Launch.

## DSE recommendation

Approve the one-way consequence before changing the VM back to Standard security.

## Article

## Source facts

Microsoft documents rollback from Trusted Launch to non-Trusted-Launch Gen2 by setting securityType to Standard. It calls this a one-way operation: Trusted Launch cannot subsequently be re-enabled on that same VM. The portal does not support this rollback, and the documented API minimum is 2025-11-01. The CLI and PowerShell procedures deallocate the VM before changing its security type. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm).

## Applicability

Use this review for an existing Gen2 VM’s security rollback, not as a procedure for returning a converted VM to Gen1. Check the current supported client versions and full prerequisites. Identify the application’s outage allowance and the security owner’s reason for removing the protection.

## DSE recommendation

Approve the one-way consequence before changing the VM back to Standard security. Have the recovery owner preserve an appropriate known-good recovery path before the original upgrade and distinguish that recovery from an in-place security change. Document how any future requirement for Trusted Launch would be met without assuming a simple toggle on the same resource.

## Verification

Rehearse the approved recovery decision on a representative test resource and inspect the resulting security profile after the supported operation. Verify boot, authorized access, and the application’s critical workflow before closing the change. Retain the deallocation window and observed state with the risk decision. Do not describe a successful return to Standard as proof that the original security setting can later be restored through the same operation.

## Official references

[Microsoft Learn: Enable Trusted Launch on existing Gen2 VMs](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm). Source reviewed September 9, 2026.

## Primary reference

- Name: Enable Trusted launch on existing Gen2 VMs - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Plan Trusted Launch rollback as a one-way security transition,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-093-plan-trusted-launch-rollback-as-a-one-way-security-transition/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
