Is UEFI lock required for Encrypted Azure VM

Farzana Mustafa 171 Reputation points
2023-09-15T01:35:00.01+00:00

Hello,

We are asked to apply a New Security Control –“ Protective Process Light for LSASS should be enabled with a UEFI lock.”

We are using Gen2 Azure Windows Server 2019 and selected 'Standard' as security type when the VMs were created.

The OS disk has encryption enabled using SSE with PMK & ADE. Also, using Azure Disk Encryption in the Extension.

Our question is do we require UEFI lock for these VMs? Will it cause any issue?

Thanks in advance.

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,988 questions
Azure Disk Encryption
Azure Disk Encryption
An Azure service for virtual machines (VMs) that helps address organizational security and compliance requirements by encrypting the VM boot and data disks with keys and policies that are controlled in Azure Key Vault.
174 questions
0 comments No comments
{count} votes

Accepted answer
  1. Prrudram-MSFT 25,156 Reputation points
    2023-09-18T17:13:42.01+00:00

    Hi @Farzana Mustafa

    The security control you mentioned, "Protective Process Light for LSASS should be enabled with a UEFI lock," is a best practice for securing Windows servers. It is recommended to enable this security control to protect against credential theft attacks.

    Regarding your question, enabling UEFI lock on your Azure Windows Server 2019 VMs should not cause any issues as long as the VMs are compatible with UEFI. Gen2 Azure VMs support UEFI boot mode, so you should be able to enable UEFI lock without any issues.

    However, before enabling UEFI lock, I would recommend you to check if your VMs are compatible with UEFI and if there are any specific requirements for enabling UEFI lock on Azure VMs. You can refer to the document "Secure the Windows 10 boot process with Secure Boot and UEFI" for more information on how to enable UEFI lock on Windows servers.

    Additionally, you should also test the UEFI lock after enabling it to ensure that the VMs are booting up properly and there are no issues.

    I hope this helps you to make an informed decision on enabling UEFI lock on your Azure Windows Server 2019 VMs.

    <If this does answer your question, please accept it as the answer as a token of appreciation.>

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.