Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs). Covers Confidential VMs (AMD SEV-SNP, Intel TDX), Confidential containers on AKS (Kata + AMD SEV-SNP), confidential GPU VMs (NVIDIA H100 with TDX), Azure Key Vault Managed HSM and Premium with secure-key-release for confidential workloads, attestation (Microsoft Azure Attestation service), confidential ledger, scenarios (multi-party data sharing, regulated workload isolation, AI training on sensitive data), key-release policies tying secrets to attested TEE state, and decision criteria vs CMK/Customer Key. WHEN: Azure Confidential Computing, AMD SEV-SNP, Intel TDX, confidential VM, confidential AKS container, confidential GPU H100, Azure Attestation, secure key release, multi-party computation, confidential AI, encrypted memory Azure, hardware enclave Azure. DO NOT USE for general data-at-rest CMK (use azure-key-vault), application encryption SDK only, or non-Azure TEE design.
$npx -y skills add vinayaklatthe/microsoft-security-skills --skill azure-confidential-computingInstalls into the current project.
Run `npx skills use "https://github.com/vinayaklatthe/microsoft-security-skills" --skill "vinayaklatthe/microsoft-security-skills/azure-confidential-computing"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/vinayaklatthe/microsoft-security-skills" that are relevant to the current task. Run `npx skills add "https://github.com/vinayaklatthe/microsoft-security-skills"` and select the relevant skills, then follow their instructions.