What you need to know
Is setting the Azure FIPS 140-3 extension-encryption flag sufficient to establish a working Linux extension path?
Potentially affected
Linux Azure VMs preparing for FIPS 140-3 extension-encryption support; this is a technical readiness check, not a compliance certification.
DSE recommendation
Record platform opt-in, guest configuration, agent readiness, and protected-settings execution as separate acceptance checks.
Source facts
Azure’s Linux FIPS 140-3 extension support requires per-VM platform opt-in as well as guest FIPS configuration and a compatible agent. Microsoft specifies Goal State Agent version 2.14.0.1 or later and validation of extension functionality. It warns against production opt-in on RHEL 9.5/9.6 with WALinuxAgent 2.7.0.6: after enablement and reboot, the agent can loop instead of becoming ready, preventing extensions from functioning. The documented RHEL workaround is for testing only. Microsoft Learn.
Applicability
Use this technical readiness check for a Linux VM whose requirements call for the newer extension-encryption behavior. Inventory the actual distribution and both agent components before applying a platform flag. This article does not certify the workload or recommend using a test workaround in production.
DSE recommendation
Record platform opt-in, guest configuration, agent readiness, and protected-settings execution as separate acceptance checks. Assign the guest configuration and extension tests to named operational owners. Hold a known affected RHEL/agent combination for a supported resolution rather than masking its readiness failure with the source’s test-only patch.
Verification
On an approved test VM, inspect the platform property and guest configuration, then verify that the agent reaches Ready. Exercise a benign extension operation that actually uses protected settings and inspect its completion. Retain the exact versions and test result without including decrypted settings in the evidence. An enabled property alone should not close the investigation if the agent or extension path remains broken.
Official references
Microsoft Learn: Linux guest-agent and extension FIPS 140-3 support. Source reviewed September 9, 2026.
Review the official source
FIPS 140-3 Support for Azure Linux VM Extensions and Guest Agent - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE