What you need to know
Can an existing Azure Gen2 VM be freely toggled between Trusted Launch and Standard security?
Potentially affected
Owners reviewing rollback for an existing Azure Gen2 VM upgraded to Trusted Launch.
DSE recommendation
Approve the one-way consequence before changing the VM back to Standard security.
Source facts
Microsoft documents rollback from Trusted Launch to non-Trusted-Launch Gen2 by setting securityType to Standard. It calls this a one-way operation: Trusted Launch cannot subsequently be re-enabled on that same VM. The portal does not support this rollback, and the documented API minimum is 2025-11-01. The CLI and PowerShell procedures deallocate the VM before changing its security type. Microsoft Learn.
Applicability
Use this review for an existing Gen2 VM’s security rollback, not as a procedure for returning a converted VM to Gen1. Check the current supported client versions and full prerequisites. Identify the application’s outage allowance and the security owner’s reason for removing the protection.
DSE recommendation
Approve the one-way consequence before changing the VM back to Standard security. Have the recovery owner preserve an appropriate known-good recovery path before the original upgrade and distinguish that recovery from an in-place security change. Document how any future requirement for Trusted Launch would be met without assuming a simple toggle on the same resource.
Verification
Rehearse the approved recovery decision on a representative test resource and inspect the resulting security profile after the supported operation. Verify boot, authorized access, and the application’s critical workflow before closing the change. Retain the deallocation window and observed state with the risk decision. Do not describe a successful return to Standard as proof that the original security setting can later be restored through the same operation.
Official references
Microsoft Learn: Enable Trusted Launch on existing Gen2 VMs. Source reviewed September 9, 2026.
Review the official source
Enable Trusted launch on existing Gen2 VMs - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE