You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
️✔️PowerShell Core - Windows️✔️Windows PowerShell - Windows
⚠️Az.Migrate
️✔️Build
️✔️PowerShell Core - Windows️✔️Windows PowerShell - Windows
️✔️Breaking Change Check
️✔️PowerShell Core - Windows️✔️Windows PowerShell - Windows
⚠️Signature Check
⚠️PowerShell Core - Windows
Type
Cmdlet
Description
Remediation
⚠️
Get-AzMigrateJob
Get-AzMigrateJob Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateJob
Get-AzMigrateJob changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateLocalJob
Get-AzMigrateLocalJob Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateLocalJob
Get-AzMigrateLocalJob changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateLocalReplicationFabric
Get-AzMigrateLocalReplicationFabric Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateLocalReplicationFabric
Get-AzMigrateLocalReplicationFabric changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateLocalServerReplication
Get-AzMigrateLocalServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateLocalServerReplication
Get-AzMigrateLocalServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateProject
Get-AzMigrateProject Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateProject
Get-AzMigrateProject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateReplicationFabric
Get-AzMigrateReplicationFabric Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateReplicationFabric
Get-AzMigrateReplicationFabric changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateReplicationPolicy
Get-AzMigrateReplicationPolicy Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateReplicationPolicy
Get-AzMigrateReplicationPolicy changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateReplicationProtectionContainer
Get-AzMigrateReplicationProtectionContainer Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateReplicationProtectionContainer
Get-AzMigrateReplicationProtectionContainer changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
Get-AzMigrateReplicationProtectionContainerMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
Get-AzMigrateReplicationProtectionContainerMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateReplicationRecoveryServicesProvider
Get-AzMigrateReplicationRecoveryServicesProvider Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateReplicationRecoveryServicesProvider
Get-AzMigrateReplicationRecoveryServicesProvider changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateRunAsAccount
Get-AzMigrateRunAsAccount Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateRunAsAccount
Get-AzMigrateRunAsAccount changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateServerMigrationStatus
Get-AzMigrateServerMigrationStatus Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateServerMigrationStatus
Get-AzMigrateServerMigrationStatus changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateServerReplication
Get-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateServerReplication
Get-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateSolution
Get-AzMigrateSolution Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateSolution
Get-AzMigrateSolution changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateDiskMapping
New-AzMigrateDiskMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
New-AzMigrateDiskMapping
New-AzMigrateDiskMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateLocalDiskMappingObject
New-AzMigrateLocalDiskMappingObject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateLocalNicMappingObject
New-AzMigrateLocalNicMappingObject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateNicMapping
New-AzMigrateNicMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
New-AzMigrateNicMapping
New-AzMigrateNicMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateServerReplication
New-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
New-AzMigrateServerReplication
New-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Remove-AzMigrateServerReplication
Remove-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Remove-AzMigrateServerReplication
Remove-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Restart-AzMigrateServerReplication
Restart-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Restart-AzMigrateServerReplication
Restart-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Set-AzMigrateDiskMapping
Set-AzMigrateDiskMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Set-AzMigrateDiskMapping
Set-AzMigrateDiskMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Set-AzMigrateServerReplication
Set-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Set-AzMigrateServerReplication
Set-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Start-AzMigrateServerMigration
Start-AzMigrateServerMigration Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Start-AzMigrateServerMigration
Start-AzMigrateServerMigration changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Start-AzMigrateTestMigration
Start-AzMigrateTestMigration Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Start-AzMigrateTestMigration
Start-AzMigrateTestMigration changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Start-AzMigrateTestMigrationCleanup
Start-AzMigrateTestMigrationCleanup Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Start-AzMigrateTestMigrationCleanup
Start-AzMigrateTestMigrationCleanup changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️Windows PowerShell - Windows
Type
Cmdlet
Description
Remediation
⚠️
Get-AzMigrateJob
Get-AzMigrateJob Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateJob
Get-AzMigrateJob changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateLocalJob
Get-AzMigrateLocalJob Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateLocalJob
Get-AzMigrateLocalJob changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateLocalReplicationFabric
Get-AzMigrateLocalReplicationFabric Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateLocalReplicationFabric
Get-AzMigrateLocalReplicationFabric changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateLocalServerReplication
Get-AzMigrateLocalServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateLocalServerReplication
Get-AzMigrateLocalServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateProject
Get-AzMigrateProject Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateProject
Get-AzMigrateProject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateReplicationFabric
Get-AzMigrateReplicationFabric Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateReplicationFabric
Get-AzMigrateReplicationFabric changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateReplicationPolicy
Get-AzMigrateReplicationPolicy Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateReplicationPolicy
Get-AzMigrateReplicationPolicy changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateReplicationProtectionContainer
Get-AzMigrateReplicationProtectionContainer Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateReplicationProtectionContainer
Get-AzMigrateReplicationProtectionContainer changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
Get-AzMigrateReplicationProtectionContainerMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
Get-AzMigrateReplicationProtectionContainerMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateReplicationRecoveryServicesProvider
Get-AzMigrateReplicationRecoveryServicesProvider Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateReplicationRecoveryServicesProvider
Get-AzMigrateReplicationRecoveryServicesProvider changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateRunAsAccount
Get-AzMigrateRunAsAccount Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateRunAsAccount
Get-AzMigrateRunAsAccount changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateServerMigrationStatus
Get-AzMigrateServerMigrationStatus Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateServerMigrationStatus
Get-AzMigrateServerMigrationStatus changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateServerReplication
Get-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateServerReplication
Get-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Get-AzMigrateSolution
Get-AzMigrateSolution Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Get-AzMigrateSolution
Get-AzMigrateSolution changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateDiskMapping
New-AzMigrateDiskMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
New-AzMigrateDiskMapping
New-AzMigrateDiskMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateLocalDiskMappingObject
New-AzMigrateLocalDiskMappingObject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateLocalNicMappingObject
New-AzMigrateLocalNicMappingObject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateNicMapping
New-AzMigrateNicMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
New-AzMigrateNicMapping
New-AzMigrateNicMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
New-AzMigrateServerReplication
New-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
New-AzMigrateServerReplication
New-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Remove-AzMigrateServerReplication
Remove-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Remove-AzMigrateServerReplication
Remove-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Restart-AzMigrateServerReplication
Restart-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Restart-AzMigrateServerReplication
Restart-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Set-AzMigrateDiskMapping
Set-AzMigrateDiskMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Set-AzMigrateDiskMapping
Set-AzMigrateDiskMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Set-AzMigrateServerReplication
Set-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Set-AzMigrateServerReplication
Set-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Start-AzMigrateServerMigration
Start-AzMigrateServerMigration Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Start-AzMigrateServerMigration
Start-AzMigrateServerMigration changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Start-AzMigrateTestMigration
Start-AzMigrateTestMigration Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Start-AzMigrateTestMigration
Start-AzMigrateTestMigration changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️
Start-AzMigrateTestMigrationCleanup
Start-AzMigrateTestMigrationCleanup Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute.
Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️
Start-AzMigrateTestMigrationCleanup
Start-AzMigrateTestMigrationCleanup changes the confirm impact. Please ensure that the change in ConfirmImpact is justified
Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
️✔️Help Example Check
️✔️PowerShell Core - Windows️✔️Windows PowerShell - Windows
️✔️Help File Existence Check
️✔️PowerShell Core - Windows️✔️Windows PowerShell - Windows
️✔️File Change Check
️✔️PowerShell Core - Windows️✔️Windows PowerShell - Windows
️✔️UX Metadata Check
️✔️PowerShell Core - Windows️✔️Windows PowerShell - Windows
⚠️Test
⚠️PowerShell Core - Linux
Type
Title
Current Coverage
Last Coverage
Description
⚠️
Test Coverage Less Than 80%
59.52 %
75.61%
Test coverage cannot be lower than the number of the last release.
⚠️PowerShell Core - MacOS
Type
Title
Current Coverage
Last Coverage
Description
⚠️
Test Coverage Less Than 80%
59.52%
75.61%
Test coverage cannot be lower than the number of the last release.
⚠️PowerShell Core - Windows
Type
Title
Current Coverage
Last Coverage
Description
⚠️
Test Coverage Less Than 80%
59.52%
75.61%
Test coverage cannot be lower than the number of the last release.
⚠️Windows PowerShell - Windows
Type
Title
Current Coverage
Last Coverage
Description
⚠️
Test Coverage Less Than 80%
59.52%
75.61%
Test coverage cannot be lower than the number of the last release.
Exposes the DataReplication SecurityOption input on New-AzMigrateLocalServerReplication and Set-AzMigrateLocalServerReplication so callers can request Secure Boot or Trusted Launch on the migrated target VM. Accepts None, SecureBootEnabled and TrustedLaunch; EnablevTPM is deliberately not exposed because the service always rejects it (error 2109020).
The property is only assigned when the parameter is supplied, so omitting it leaves SecurityOption null and preserves the existing behaviour where the target mirrors the discovered source. A client-side guard rejects any option other than None for Generation 1 target VMs, ahead of the service round-trip. No swagger repin or regeneration was needed - the 2026-05-01 models already carry securityOption; only the custom cmdlet layer and its generated docs changed.
Adds 4 tests covering the parameter surface on both cmdlets, the allowed value set, and rejection of unsupported values. Local playback: 55 passed, 0 failed, 23 skipped.
Description
Adds Trusted Launch / Secure Boot support to Azure Local replication, on top of the
DataReplication API bump to 2026-05-01.
New parameters
New-AzMigrateLocalServerReplication and Set-AzMigrateLocalServerReplication gain two
parameters:
Parameter
Values
Meaning
-TargetVMSecurityOption
Standard, TrustedLaunch
Security type of the target VM. TrustedLaunch enables Secure Boot and vTPM.
-EnableSecureBoot
true, false
Secure Boot on the target VM. Implied true by TrustedLaunch.
These are the user-facing values and deliberately differ from the service's securityOption field. The wire values None, SecureBootEnabled and EnablevTPM are not
exposed: EnablevTPM means vTPM without Secure Boot, which the service always rejects
(error 2109020), and None / SecureBootEnabled are outcomes of the two parameters rather
than things a caller should have to reason about. This matches the split already used by New-AzMigrateServerReplication (-TargetVMSecurityType + -TargetVMSecureBootEnabled).
Mapping to securityOption
Resolved state
Sent
Gen 1
None
Gen 2, TrustedLaunch
TrustedLaunch
Gen 2, Standard + Secure Boot on
SecureBootEnabled
Gen 2, Standard + Secure Boot off
None
Omitting both parameters leaves the property unset, so existing callers are unaffected.
Validation
Rejected client-side, before any service call:
-TargetVMSecurityOption TrustedLaunch with -EnableSecureBoot false — a parameter
contradiction, evaluated before the module dependency checks so it does not require Az.ResourceGraph to be installed.
Secure Boot or Trusted Launch requested against a Generation 1 target.
A Generation 2 source that already has Secure Boot enabled, asked to migrate with -EnableSecureBoot false. secureBootEnabled is absent from the OffAzure 2020-01-01
models this module is generated against, so Get-AzMigrateSourceSecureBootState reads that
one field at 2024-12-01-preview. This check fails open — if the field is absent, the
call fails, or a non-200 comes back, the request proceeds and AzStackHCISecurityOptionDowngradeNotAllowed (2109019) remains the backstop.
Regenerating against a newer OffAzure version was considered and rejected: every operationId
was renamed to a *Controller_* convention after 2020-01-01 (39 of 41 gone), and only the
preview carries secureBootEnabled for VMware as well as Hyper-V.
Also included
Initialize-AzMigrateLocalReplicationInfrastructure now grants Storage Account Contributor
instead of Contributor on the cache storage account, narrowing the privilege granted to the
replication vault identity and the source/target appliance applications.
Verified live against a Generation 2 Hyper-V source with Secure Boot enabled: the
enable-protection request carried "securityOption": "TrustedLaunch" and the service accepted
it. The corresponding test is tagged LiveOnly — the create path cannot be recorded, because
the cmdlet's pre-existence lookup returns 404 on a first run and the recorder does not persist
that exchange, which is the same limitation behind the already-skipped ByIdDefaultUser / ByIdPowerUser cases and the LiveOnlySet-AzMigrateLocalServerReplication suite.
Mandatory Checklist
Please choose the target release of Azure PowerShell. (⚠️Target release is a different concept from API readiness. Please click below links for details.)
…cal replication
Exposes the DataReplication SecurityOption input on New-AzMigrateLocalServerReplication and Set-AzMigrateLocalServerReplication so callers can request Secure Boot or Trusted Launch on the migrated target VM. Accepts None, SecureBootEnabled and TrustedLaunch; EnablevTPM is deliberately not exposed because the service always rejects it (error 2109020).
The property is only assigned when the parameter is supplied, so omitting it leaves SecurityOption null and preserves the existing behaviour where the target mirrors the discovered source. A client-side guard rejects any option other than None for Generation 1 target VMs, ahead of the service round-trip. No swagger repin or regeneration was needed - the 2026-05-01 models already carry securityOption; only the custom cmdlet layer and its generated docs changed.
Adds 4 tests covering the parameter surface on both cmdlets, the allowed value set, and rejection of unsupported values. Local playback: 55 passed, 0 failed, 23 skipped.
This wording contradicts the implementation: None is explicitly accepted for a Generation 1 target, while only SecureBootEnabled and TrustedLaunch are rejected there. Please describe the Generation 2 restriction only for those two security-enabling values so the parameter help does not tell users that every use is Generation 2-only.
# Specifies the security configuration of the target VM. 'SecureBootEnabled' enables Secure Boot. 'TrustedLaunch' enables Secure Boot and vTPM. Only supported for Generation 2 target VMs.
The generated custom-properties models currently contain no SecurityOption member (the base update model exposes only InstanceType), so this assignment cannot be serialized and will fail when the new parameter is used. The generated model/interface and JSON metadata must be updated or regenerated from a schema containing securityOption; changing only the custom cmdlet layer is insufficient.
The new Set path is likewise not exercised by the tests: the Set test file still contains only its existing live-only case, while the added tests merely inspect the command definition. This leaves both the Generation 1 validation and the customPropertiesUpdate.SecurityOption assignment unverified; add a Generation 2 playback/unit case that checks the update payload and a Generation 1 rejection case.
if ($HasTargetVMSecurityOption) {
if ($customProperties.HyperVGeneration -eq "1" -and
$TargetVMSecurityOption -ne $SecurityOptions.None) {
throw "-TargetVMSecurityOption '$TargetVMSecurityOption' requires a Generation 2 target VM. Protected item '$TargetObjectID' has a Generation 1 target VM."
}
$customPropertiesUpdate.SecurityOption = $TargetVMSecurityOption
This description has the same contradiction as the New cmdlet: the code permits -TargetVMSecurityOption None on Generation 1, so saying the option is only supported for Generation 2 is inaccurate. Restrict the Generation 2 statement to SecureBootEnabled and TrustedLaunch.
# Specifies the security configuration of the target VM. 'SecureBootEnabled' enables Secure Boot. 'TrustedLaunch' enables Secure Boot and vTPM. Only supported for Generation 2 target VMs.
src/Migrate/Migrate/ChangeLog.md:23
The release note says that only Generation 2 target VMs are supported, but the new guard deliberately permits None for Generation 1 targets. Please state that only the Secure Boot/Trusted Launch values require Generation 2, otherwise users may incorrectly believe the parameter cannot be used with Generation 1 targets.
* Added 'TargetVMSecurityOption' parameter to 'New-AzMigrateLocalServerReplication' and 'Set-AzMigrateLocalServerReplication' to configure Secure Boot and Trusted Launch on the target virtual machine (VM). Supported values are 'None', 'SecureBootEnabled' and 'TrustedLaunch'; only Generation 2 target VMs are supported
…on the cache storage account
Initialize-AzMigrateLocalReplicationInfrastructure granted the broad Contributor role on the cache storage account to the replication vault managed identity and to the source and target appliance applications. Data-plane access already comes from Storage Blob Data Contributor, so the management role only needs to cover storage account operations such as listing keys. Narrows it to Storage Account Contributor (17d1049b-9a84-46fb-8f53-869881c3d3ab).
Existing Contributor assignments are left in place; this only changes what newly initialized infrastructure is granted. The four checks in the permission-verification retry loop move to the new role alongside the three grant sites, so the loop still converges. Fixes AB#39606529.
The new tests only inspect parameter metadata and ValidateSet binding; they never exercise this assignment or the Generation 1 guard. A regression that drops SecurityOption from the request (or stops rejecting non-None for Gen 1) would therefore pass. Add a mocked/playback test that invokes the cmdlet with SecureBootEnabled/TrustedLaunch and verifies the submitted custom properties, plus the Gen 1 failure path. src/Migrate/Migrate.Autorest/custom/Set-AzMigrateLocalServerReplication.ps1:229
The new tests only inspect parameter metadata and ValidateSet binding; they do not cover this update payload or the Generation 1 guard. A regression that omits SecurityOption from the Set request (or permits a non-None value for Gen 1) would pass. Add a mocked/playback test that verifies the update request and the Gen 1 failure path.
The description says this parameter is only supported for Generation 2 targets, but None is explicitly accepted and the implementation allows it on Generation 1 ($TargetVMSecurityOption -ne $SecurityOptions.None). Please clarify that only SecureBootEnabled and TrustedLaunch require Generation 2, and regenerate the matching markdown help so users are not told that the valid None value is unsupported on Gen1.
# Specifies the security configuration of the target VM. 'SecureBootEnabled' enables Secure Boot. 'TrustedLaunch' enables Secure Boot and vTPM. Only supported for Generation 2 target VMs.
The description says this parameter is only supported for Generation 2 targets, but None is explicitly accepted and the implementation allows it on Generation 1 ($TargetVMSecurityOption -ne $SecurityOptions.None). Please clarify that only SecureBootEnabled and TrustedLaunch require Generation 2, and regenerate the matching markdown help so users are not told that the valid None value is unsupported on Gen1.
# Specifies the security configuration of the target VM. 'SecureBootEnabled' enables Secure Boot. 'TrustedLaunch' enables Secure Boot and vTPM. Only supported for Generation 2 target VMs.
The guard below rejects only non-None options for Generation 1, so None is valid for Generation 1 as well. This description incorrectly says the parameter is only supported for Generation 2 and can mislead users; scope the Generation 2 restriction to SecureBootEnabled and TrustedLaunch.
### -TargetVMSecurityOption
Specifies the security configuration of the target VM.
'SecureBootEnabled' enables Secure Boot.
'TrustedLaunch' enables Secure Boot and vTPM.
Only supported for Generation 2 target VMs.
The guard below rejects only non-None options for Generation 1, so None is valid for Generation 1 as well. This description incorrectly says the parameter is only supported for Generation 2 and can mislead users; scope the Generation 2 restriction to SecureBootEnabled and TrustedLaunch.
### -TargetVMSecurityOption
Specifies the security configuration of the target VM.
'SecureBootEnabled' enables Secure Boot.
'TrustedLaunch' enables Secure Boot and vTPM.
Only supported for Generation 2 target VMs.
src/Migrate/Migrate/ChangeLog.md:23
The implementation permits -TargetVMSecurityOption None on Generation 1 targets, but this changelog entry says that only Generation 2 targets are supported. Please describe the restriction as applying to SecureBootEnabled and TrustedLaunch so the release note matches the actual behavior.
* Added 'TargetVMSecurityOption' parameter to 'New-AzMigrateLocalServerReplication' and 'Set-AzMigrateLocalServerReplication' to configure Secure Boot and Trusted Launch on the target virtual machine (VM). Supported values are 'None', 'SecureBootEnabled' and 'TrustedLaunch'; only Generation 2 target VMs are supported
…EnableSecureBoot
Reshapes the security surface to match the Azure Migrate portal. TargetVMSecurityOption now accepts Standard or TrustedLaunch (the user-facing security type) and a separate EnableSecureBoot controls Secure Boot. The two collapse onto the single service securityOption field, so no swagger change is needed: TrustedLaunch maps to TrustedLaunch, Standard plus Secure Boot to SecureBootEnabled, and Standard without it to None.
TrustedLaunch implies Secure Boot, so passing -EnableSecureBoot false alongside it is rejected up front, before any service lookup. The Generation 1 guard runs after the generation is derived because it needs it. -TargetVMSecurityOption Standard on its own omits the property on New so the target keeps inheriting the source, and sends SecureBootEnabled on Set so that leaving Trusted Launch drops vTPM without silently dropping Secure Boot, matching the portal.
PowerShell cannot pre-validate the no-downgrade rule: secureBootEnabled is absent from the OffAzure 2020-01-01 discovery models this module pins, and the portal reads it from 2024-12-01-preview. Requesting Standard without Secure Boot against a source that has it enabled is therefore left to the service, which rejects it with AzStackHCISecurityOptionDowngradeNotAllowed.
Local playback: 55 passed, 0 failed, 23 skipped.
When -TargetVMSecurityOption Standard is supplied without -EnableSecureBoot, this branch intentionally leaves SecurityOption unset, so the service inherits the source security setting instead of applying the requested Standard option. Since this parameter is the user-facing choice of target security type, map Standard to None (or otherwise send the corresponding wire value) whenever it is explicitly supplied.
# Only send securityOption once a choice is expressed. '-TargetVMSecurityOption Standard'
# on its own is not a choice about Secure Boot, so the target keeps inheriting the source.
if ($securityType -eq $TargetVMSecurityTypes.TrustedLaunch) {
$customProperties.SecurityOption = $SecurityOptions.TrustedLaunch
}
elseif ($HasEnableSecureBoot) {
$customProperties.SecurityOption = if ($secureBootEnabled) { $SecurityOptions.SecureBootEnabled } else { $SecurityOptions.None }
}
The added tests verify parameter metadata and two binding-time errors, but they never exercise the new payload mapping (TrustedLaunch, SecureBootEnabled, or None) or the Generation 1 guard in either cmdlet. A regression in the code that actually assigns customProperties.SecurityOption would therefore pass these tests; add playback/unit coverage for both cmdlets and the Gen1 cases.
New-/Set-AzMigrateLocalServerReplication now reject -EnableSecureBoot 'false' when the Gen 2 source server already has Secure Boot on, instead of letting the service fail the request with AzStackHCISecurityOptionDowngradeNotAllowed (2109019).
secureBootEnabled is absent from the OffAzure 2020-01-01 models the module is generated against, so Get-AzMigrateSourceSecureBootState reads that single field at 2024-12-01-preview via Invoke-AzRestMethod. Regenerating against a newer OffAzure version was rejected: every operationId was renamed to a *Controller_* convention after 2020-01-01 (39 of 41 gone), and only the preview carries the field for VMware as well as Hyper-V.
The check fails open - an absent field, a non-200, or a transport failure returns null and the request proceeds, leaving the service as the authority.
Error messages report the discovered display name rather than the ARM resource name, which is an opaque synthetic id for VMware sources.
New-AzMigrateLocalServerReplication deliberately leaves SecurityOption unset for -TargetVMSecurityOption Standard without -EnableSecureBoot (lines 780-781), preserving source inheritance. This Set path instead forces $secureBootEnabled = $true when the same parameters are supplied, then writes SecureBootEnabled and rejects Generation 1 targets. The two cmdlets therefore give the same public input different behavior; reuse a single mapping so Standard has consistent semantics.
New-/Set-AzMigrateLocalServerReplication validated -TargetVMSecurityOption 'TrustedLaunch' with -EnableSecureBoot 'false' only after CheckResourceGraphModuleDependency and CheckResourcesModuleDependency had run. On agents without Az.ResourceGraph installed the cmdlet failed with a module-install message instead, so EnableSecureBoot-RejectsTrustedLaunchOptOut failed in CI while passing locally.
The contradiction is purely between two parameters and needs no Azure modules to detect, so it is now evaluated immediately after the helper imports.
Set-AzMigrateLocalServerReplication defaults secureBootEnabled to true when -TargetVMSecurityOption is given without -EnableSecureBoot, so that leaving Trusted Launch keeps Secure Boot on a Gen 2 target the way the portal does. That default also tripped the Gen 2 guard, so asking for 'Standard' - the least restrictive option - on a Gen 1 protected item failed with a message saying Secure Boot requires Generation 2.
The guard now fires only for an explicit Trusted Launch or -EnableSecureBoot 'true' request. On Gen 1 there is no Secure Boot to inherit, so the option resolves to None. Gen 2 behaviour is unchanged, and New- was never affected because it has no inherit default.
Reported by Copilot review on PR 30152.
This changes future checks and grants to Storage Account Contributor, but it never removes the existing Contributor assignment. On infrastructures initialized before this change, rerunning the cmdlet leaves the broad role in place, so the stated replacement does not reduce privileges. Add a narrowly scoped migration/removal of the old assignment, or explicitly document that this only affects new assignments.
…uest
The existing tests only covered parameter metadata and ValidateSet binding, so a regression that dropped the SecurityOption assignment, or sent the wrong value, would still have passed. Reported by Copilot review on PR 30152.
The service accepts securityOption on create but returns null for it on subsequent GETs, the same as migrateAsArcVM, so the value cannot be asserted by reading the protected item back. The test instead captures the outgoing PUT through -HttpPipelinePrepend and asserts the serialized body.
Tagged LiveOnly because the create path cannot be recorded: New-AzMigrateLocalServerReplication rejects an already-replicating VM using a pre-existence lookup that returns 404 on a first run, and the test recorder does not persist that exchange, so playback always concludes the VM is already in replication. This is the same limitation behind the skipped ByIdDefaultUser and ByIdPowerUser cases and the LiveOnly Set-AzMigrateLocalServerReplication suite.
Verified against a live Hyper-V source with Secure Boot enabled; the recorded request contained securityOption TrustedLaunch and the service echoed it back on create.
For cache accounts initialized by an older module version, the identities already have the old Contributor assignment at this same scope. This code only checks/adds Storage Account Contributor, so rerunning initialization leaves the broad Contributor grant in place and does not achieve the least-privilege change described in the changelog. After the replacement assignment is confirmed, remove only the module-created old role assignment (or otherwise migrate existing assignments) for the vault/source/target identities.
Map Standard security option to the None wire value
Standard is accepted by the parameter but this branch leaves SecurityOption unset; only TrustedLaunch is assigned here, so -TargetVMSecurityOption Standard silently falls back to source-inheritance instead of requesting the standard/no-security wire value. The existing migration cmdlet treats Standard as incompatible with Secure Boot (src/Migrate/Migrate.Autorest/custom/New-AzMigrateServerReplication.ps1:588-592), so assign $SecurityOptions.None when Standard is explicitly supplied (and add a request-level test).
When -TargetVMSecurityOption Standard is supplied without -EnableSecureBoot, this condition sets $secureBootEnabled to $true. The subsequent logic therefore rejects Generation 1 targets and sends SecureBootEnabled for Generation 2 targets, making Standard behave like Secure Boot rather than the standard/no-security option. Only TrustedLaunch should force Secure Boot; leave the value false when Standard is selected without an explicit Secure Boot request.
Update PR description to match security option parameters
src/Migrate/Migrate/ChangeLog.md:23
The changed user-facing contract here is Standard/TrustedLaunch, but the PR description still says TargetVMSecurityOption accepts the wire values None, SecureBootEnabled, and TrustedLaunch. Those wire values are rejected by the new ValidateSet, so please update the PR description to match the actual parameter contract (or change the implementation if the wire-value contract is intended).
‼️ DO NOT MERGE THIS PR ‼️
This PR was labeled "Do Not Merge" because it contains code change that cannot be merged. Please contact the reviewer for more information.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖 PR Validation —⚠️ Review suggested
️✔️Az.Accounts
Exposes the DataReplication SecurityOption input on New-AzMigrateLocalServerReplication and Set-AzMigrateLocalServerReplication so callers can request Secure Boot or Trusted Launch on the migrated target VM. Accepts None, SecureBootEnabled and TrustedLaunch; EnablevTPM is deliberately not exposed because the service always rejects it (error 2109020).
The property is only assigned when the parameter is supplied, so omitting it leaves SecurityOption null and preserves the existing behaviour where the target mirrors the discovered source. A client-side guard rejects any option other than None for Generation 1 target VMs, ahead of the service round-trip. No swagger repin or regeneration was needed - the 2026-05-01 models already carry securityOption; only the custom cmdlet layer and its generated docs changed.
Adds 4 tests covering the parameter surface on both cmdlets, the allowed value set, and rejection of unsupported values. Local playback: 55 passed, 0 failed, 23 skipped.
Description
Adds Trusted Launch / Secure Boot support to Azure Local replication, on top of the
DataReplication API bump to
2026-05-01.New parameters
New-AzMigrateLocalServerReplicationandSet-AzMigrateLocalServerReplicationgain twoparameters:
-TargetVMSecurityOptionStandard,TrustedLaunchTrustedLaunchenables Secure Boot and vTPM.-EnableSecureBoottrue,falsetruebyTrustedLaunch.These are the user-facing values and deliberately differ from the service's
securityOptionfield. The wire valuesNone,SecureBootEnabledandEnablevTPMare notexposed:
EnablevTPMmeans vTPM without Secure Boot, which the service always rejects(error 2109020), and
None/SecureBootEnabledare outcomes of the two parameters ratherthan things a caller should have to reason about. This matches the split already used by
New-AzMigrateServerReplication(-TargetVMSecurityType+-TargetVMSecureBootEnabled).Mapping to
securityOptionNoneTrustedLaunchTrustedLaunchStandard+ Secure Boot onSecureBootEnabledStandard+ Secure Boot offNoneOmitting both parameters leaves the property unset, so existing callers are unaffected.
Validation
Rejected client-side, before any service call:
-TargetVMSecurityOption TrustedLaunchwith-EnableSecureBoot false— a parametercontradiction, evaluated before the module dependency checks so it does not require
Az.ResourceGraphto be installed.-EnableSecureBoot false.secureBootEnabledis absent from the OffAzure2020-01-01models this module is generated against, so
Get-AzMigrateSourceSecureBootStatereads thatone field at
2024-12-01-preview. This check fails open — if the field is absent, thecall fails, or a non-200 comes back, the request proceeds and
AzStackHCISecurityOptionDowngradeNotAllowed(2109019) remains the backstop.Regenerating against a newer OffAzure version was considered and rejected: every
operationIdwas renamed to a
*Controller_*convention after2020-01-01(39 of 41 gone), and only thepreview carries
secureBootEnabledfor VMware as well as Hyper-V.Also included
Initialize-AzMigrateLocalReplicationInfrastructurenow grants Storage Account Contributorinstead of Contributor on the cache storage account, narrowing the privilege granted to the
replication vault identity and the source/target appliance applications.
Testing
Migrate.Autorestplayback suite: 57 passed, 0 failed, 23 skipped.Verified live against a Generation 2 Hyper-V source with Secure Boot enabled: the
enable-protection request carried
"securityOption": "TrustedLaunch"and the service acceptedit. The corresponding test is tagged
LiveOnly— the create path cannot be recorded, becausethe cmdlet's pre-existence lookup returns 404 on a first run and the recorder does not persist
that exchange, which is the same limitation behind the already-skipped
ByIdDefaultUser/ByIdPowerUsercases and theLiveOnlySet-AzMigrateLocalServerReplicationsuite.Mandatory Checklist
Please choose the target release of Azure PowerShell. (⚠️ Target release is a different concept from API readiness. Please click below links for details.)
Check this box to confirm: I have read the Submitting Changes section of
CONTRIBUTING.mdand reviewed the following information:ChangeLog.mdfile(s) appropriatelysrc/{{SERVICE}}/{{SERVICE}}/ChangeLog.md.## Upcoming Releaseheader in the past tense.ChangeLog.mdif no new release is required, such as fixing test case only.