Deployment Security Settings Args
The SecuritySettings of AzureStackHCI Cluster.
Constructors
Properties
When set to true, BitLocker XTS_AES 256-bit encryption is enabled for all data-at-rest on the OS volume of your Azure Stack HCI cluster. This setting is TPM-hardware dependent.
When set to true, BitLocker XTS-AES 256-bit encryption is enabled for all data-at-rest on your Azure Stack HCI cluster shared volumes.
When set to true, Credential Guard is enabled.
When set to true, the security baseline is re-applied regularly.
By default, Secure Boot is enabled on your Azure HCI cluster. This setting is hardware dependent.
By default, Hypervisor-protected Code Integrity is enabled on your Azure HCI cluster.
When set to true, all the side channel mitigations are enabled
When set to true, cluster east-west traffic is encrypted.
When set to true, the SMB default instance requires sign in for the client and server services.
WDAC is enabled by default and limits the applications and the code that you can run on your Azure Stack HCI cluster.