Skip to content

Az.Migrate: add TargetVMSecurityOption for Trusted Launch on Azure Lo… - #30152

Open
anhdinh-msft wants to merge 7 commits into
Azure:mainfrom
anhdinh-msft:user/anhdinh/tvm-security-option
Open

anhdinh-msft wants to merge 7 commits into
Azure:mainfrom
anhdinh-msft:user/anhdinh/tvm-security-option

Conversation

@anhdinh-msft

@anhdinh-msft anhdinh-msft commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

🤖 PR Validation — ⚠️ Review suggested

Tests
⚠️ 20/20
️✔️Az.Accounts
️✔️Build
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
⚠️Az.Migrate
️✔️Build
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
️✔️Breaking Change Check
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
⚠️Signature Check
⚠️PowerShell Core - Windows
Type Cmdlet Description Remediation
⚠️ Get-AzMigrateJob Get-AzMigrateJob Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateJob Get-AzMigrateJob changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateLocalJob Get-AzMigrateLocalJob Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateLocalJob Get-AzMigrateLocalJob changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateLocalReplicationFabric Get-AzMigrateLocalReplicationFabric Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateLocalReplicationFabric Get-AzMigrateLocalReplicationFabric changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateLocalServerReplication Get-AzMigrateLocalServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateLocalServerReplication Get-AzMigrateLocalServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateProject Get-AzMigrateProject Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateProject Get-AzMigrateProject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationFabric Get-AzMigrateReplicationFabric Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationFabric Get-AzMigrateReplicationFabric changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationPolicy Get-AzMigrateReplicationPolicy Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationPolicy Get-AzMigrateReplicationPolicy changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationProtectionContainer Get-AzMigrateReplicationProtectionContainer Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationProtectionContainer Get-AzMigrateReplicationProtectionContainer changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationProtectionContainerMapping Get-AzMigrateReplicationProtectionContainerMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationProtectionContainerMapping Get-AzMigrateReplicationProtectionContainerMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationRecoveryServicesProvider Get-AzMigrateReplicationRecoveryServicesProvider Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationRecoveryServicesProvider Get-AzMigrateReplicationRecoveryServicesProvider changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateRunAsAccount Get-AzMigrateRunAsAccount Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateRunAsAccount Get-AzMigrateRunAsAccount changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateServerMigrationStatus Get-AzMigrateServerMigrationStatus Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateServerMigrationStatus Get-AzMigrateServerMigrationStatus changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateServerReplication Get-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateServerReplication Get-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateSolution Get-AzMigrateSolution Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateSolution Get-AzMigrateSolution changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateDiskMapping New-AzMigrateDiskMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ New-AzMigrateDiskMapping New-AzMigrateDiskMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateLocalDiskMappingObject New-AzMigrateLocalDiskMappingObject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateLocalNicMappingObject New-AzMigrateLocalNicMappingObject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateNicMapping New-AzMigrateNicMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ New-AzMigrateNicMapping New-AzMigrateNicMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateServerReplication New-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ New-AzMigrateServerReplication New-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Remove-AzMigrateServerReplication Remove-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Remove-AzMigrateServerReplication Remove-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Restart-AzMigrateServerReplication Restart-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Restart-AzMigrateServerReplication Restart-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Set-AzMigrateDiskMapping Set-AzMigrateDiskMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Set-AzMigrateDiskMapping Set-AzMigrateDiskMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Set-AzMigrateServerReplication Set-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Set-AzMigrateServerReplication Set-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Start-AzMigrateServerMigration Start-AzMigrateServerMigration Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Start-AzMigrateServerMigration Start-AzMigrateServerMigration changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Start-AzMigrateTestMigration Start-AzMigrateTestMigration Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Start-AzMigrateTestMigration Start-AzMigrateTestMigration changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Start-AzMigrateTestMigrationCleanup Start-AzMigrateTestMigrationCleanup Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Start-AzMigrateTestMigrationCleanup Start-AzMigrateTestMigrationCleanup changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️Windows PowerShell - Windows
Type Cmdlet Description Remediation
⚠️ Get-AzMigrateJob Get-AzMigrateJob Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateJob Get-AzMigrateJob changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateLocalJob Get-AzMigrateLocalJob Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateLocalJob Get-AzMigrateLocalJob changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateLocalReplicationFabric Get-AzMigrateLocalReplicationFabric Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateLocalReplicationFabric Get-AzMigrateLocalReplicationFabric changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateLocalServerReplication Get-AzMigrateLocalServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateLocalServerReplication Get-AzMigrateLocalServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateProject Get-AzMigrateProject Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateProject Get-AzMigrateProject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationFabric Get-AzMigrateReplicationFabric Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationFabric Get-AzMigrateReplicationFabric changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationPolicy Get-AzMigrateReplicationPolicy Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationPolicy Get-AzMigrateReplicationPolicy changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationProtectionContainer Get-AzMigrateReplicationProtectionContainer Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationProtectionContainer Get-AzMigrateReplicationProtectionContainer changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationProtectionContainerMapping Get-AzMigrateReplicationProtectionContainerMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationProtectionContainerMapping Get-AzMigrateReplicationProtectionContainerMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateReplicationRecoveryServicesProvider Get-AzMigrateReplicationRecoveryServicesProvider Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateReplicationRecoveryServicesProvider Get-AzMigrateReplicationRecoveryServicesProvider changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateRunAsAccount Get-AzMigrateRunAsAccount Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateRunAsAccount Get-AzMigrateRunAsAccount changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateServerMigrationStatus Get-AzMigrateServerMigrationStatus Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateServerMigrationStatus Get-AzMigrateServerMigrationStatus changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateServerReplication Get-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateServerReplication Get-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Get-AzMigrateSolution Get-AzMigrateSolution Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Get-AzMigrateSolution Get-AzMigrateSolution changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateDiskMapping New-AzMigrateDiskMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ New-AzMigrateDiskMapping New-AzMigrateDiskMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateLocalDiskMappingObject New-AzMigrateLocalDiskMappingObject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateLocalNicMappingObject New-AzMigrateLocalNicMappingObject changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateNicMapping New-AzMigrateNicMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ New-AzMigrateNicMapping New-AzMigrateNicMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ New-AzMigrateServerReplication New-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ New-AzMigrateServerReplication New-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Remove-AzMigrateServerReplication Remove-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Remove-AzMigrateServerReplication Remove-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Restart-AzMigrateServerReplication Restart-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Restart-AzMigrateServerReplication Restart-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Set-AzMigrateDiskMapping Set-AzMigrateDiskMapping Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Set-AzMigrateDiskMapping Set-AzMigrateDiskMapping changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Set-AzMigrateServerReplication Set-AzMigrateServerReplication Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Set-AzMigrateServerReplication Set-AzMigrateServerReplication changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Start-AzMigrateServerMigration Start-AzMigrateServerMigration Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Start-AzMigrateServerMigration Start-AzMigrateServerMigration changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Start-AzMigrateTestMigration Start-AzMigrateTestMigration Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Start-AzMigrateTestMigration Start-AzMigrateTestMigration changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
⚠️ Start-AzMigrateTestMigrationCleanup Start-AzMigrateTestMigrationCleanup Changes the ConfirmImpact but does not set the SupportsShouldProcess property to true in the cmdlet attribute. Determine if the cmdlet should implement ShouldProcess and if so determine if it should implement Force / ShouldContinue
⚠️ Start-AzMigrateTestMigrationCleanup Start-AzMigrateTestMigrationCleanup changes the confirm impact. Please ensure that the change in ConfirmImpact is justified Verify that ConfirmImpact is changed appropriately by the cmdlet. It is very rare for a cmdlet to change the ConfirmImpact.
️✔️Help Example Check
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
️✔️Help File Existence Check
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
️✔️File Change Check
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
️✔️UX Metadata Check
️✔️PowerShell Core - Windows
️✔️Windows PowerShell - Windows
⚠️Test
⚠️PowerShell Core - Linux
Type Title Current Coverage Last Coverage Description
⚠️ Test Coverage Less Than 80% 59.52 % 75.61% Test coverage cannot be lower than the number of the last release.
⚠️PowerShell Core - MacOS
Type Title Current Coverage Last Coverage Description
⚠️ Test Coverage Less Than 80% 59.52% 75.61% Test coverage cannot be lower than the number of the last release.
⚠️PowerShell Core - Windows
Type Title Current Coverage Last Coverage Description
⚠️ Test Coverage Less Than 80% 59.52% 75.61% Test coverage cannot be lower than the number of the last release.
⚠️Windows PowerShell - Windows
Type Title Current Coverage Last Coverage Description
⚠️ Test Coverage Less Than 80% 59.52% 75.61% Test coverage cannot be lower than the number of the last release.

Exposes the DataReplication SecurityOption input on New-AzMigrateLocalServerReplication and Set-AzMigrateLocalServerReplication so callers can request Secure Boot or Trusted Launch on the migrated target VM. Accepts None, SecureBootEnabled and TrustedLaunch; EnablevTPM is deliberately not exposed because the service always rejects it (error 2109020).

The property is only assigned when the parameter is supplied, so omitting it leaves SecurityOption null and preserves the existing behaviour where the target mirrors the discovered source. A client-side guard rejects any option other than None for Generation 1 target VMs, ahead of the service round-trip. No swagger repin or regeneration was needed - the 2026-05-01 models already carry securityOption; only the custom cmdlet layer and its generated docs changed.

Adds 4 tests covering the parameter surface on both cmdlets, the allowed value set, and rejection of unsupported values. Local playback: 55 passed, 0 failed, 23 skipped.

Description

Adds Trusted Launch / Secure Boot support to Azure Local replication, on top of the
DataReplication API bump to 2026-05-01.

New parameters

New-AzMigrateLocalServerReplication and Set-AzMigrateLocalServerReplication gain two
parameters:

Parameter Values Meaning
-TargetVMSecurityOption Standard, TrustedLaunch Security type of the target VM. TrustedLaunch enables Secure Boot and vTPM.
-EnableSecureBoot true, false Secure Boot on the target VM. Implied true by TrustedLaunch.

These are the user-facing values and deliberately differ from the service's
securityOption field. The wire values None, SecureBootEnabled and EnablevTPM are not
exposed: EnablevTPM means vTPM without Secure Boot, which the service always rejects
(error 2109020), and None / SecureBootEnabled are outcomes of the two parameters rather
than things a caller should have to reason about. This matches the split already used by
New-AzMigrateServerReplication (-TargetVMSecurityType + -TargetVMSecureBootEnabled).

Mapping to securityOption

Resolved state Sent
Gen 1 None
Gen 2, TrustedLaunch TrustedLaunch
Gen 2, Standard + Secure Boot on SecureBootEnabled
Gen 2, Standard + Secure Boot off None

Omitting both parameters leaves the property unset, so existing callers are unaffected.

Validation

Rejected client-side, before any service call:

  1. -TargetVMSecurityOption TrustedLaunch with -EnableSecureBoot false — a parameter
    contradiction, evaluated before the module dependency checks so it does not require
    Az.ResourceGraph to be installed.
  2. Secure Boot or Trusted Launch requested against a Generation 1 target.
  3. A Generation 2 source that already has Secure Boot enabled, asked to migrate with
    -EnableSecureBoot false. secureBootEnabled is absent from the OffAzure 2020-01-01
    models this module is generated against, so Get-AzMigrateSourceSecureBootState reads that
    one field at 2024-12-01-preview. This check fails open — if the field is absent, the
    call fails, or a non-200 comes back, the request proceeds and
    AzStackHCISecurityOptionDowngradeNotAllowed (2109019) remains the backstop.

Regenerating against a newer OffAzure version was considered and rejected: every operationId
was renamed to a *Controller_* convention after 2020-01-01 (39 of 41 gone), and only the
preview carries secureBootEnabled for VMware as well as Hyper-V.

Also included

Initialize-AzMigrateLocalReplicationInfrastructure now grants Storage Account Contributor
instead of Contributor on the cache storage account, narrowing the privilege granted to the
replication vault identity and the source/target appliance applications.

Testing

Migrate.Autorest playback suite: 57 passed, 0 failed, 23 skipped.

Verified live against a Generation 2 Hyper-V source with Secure Boot enabled: the
enable-protection request carried "securityOption": "TrustedLaunch" and the service accepted
it. The corresponding test is tagged LiveOnly — the create path cannot be recorded, because
the cmdlet's pre-existence lookup returns 404 on a first run and the recorder does not persist
that exchange, which is the same limitation behind the already-skipped ByIdDefaultUser /
ByIdPowerUser cases and the LiveOnly Set-AzMigrateLocalServerReplication suite.

Mandatory Checklist

  • SHOULD update ChangeLog.md file(s) appropriately
    • Update src/{{SERVICE}}/{{SERVICE}}/ChangeLog.md.
      • A snippet outlining the change(s) made in the PR should be written under the ## Upcoming Release header in the past tense.
    • Should not change ChangeLog.md if no new release is required, such as fixing test case only.
  • SHOULD regenerate markdown help files if there is cmdlet API change. Instruction
  • SHOULD have proper test coverage for changes in pull request.
  • SHOULD NOT adjust version of module manually in pull request

…cal replication

Exposes the DataReplication SecurityOption input on New-AzMigrateLocalServerReplication and Set-AzMigrateLocalServerReplication so callers can request Secure Boot or Trusted Launch on the migrated target VM. Accepts None, SecureBootEnabled and TrustedLaunch; EnablevTPM is deliberately not exposed because the service always rejects it (error 2109020).

The property is only assigned when the parameter is supplied, so omitting it leaves SecurityOption null and preserves the existing behaviour where the target mirrors the discovered source. A client-side guard rejects any option other than None for Generation 1 target VMs, ahead of the service round-trip. No swagger repin or regeneration was needed - the 2026-05-01 models already carry securityOption; only the custom cmdlet layer and its generated docs changed.

Adds 4 tests covering the parameter surface on both cmdlets, the allowed value set, and rejection of unsupported values. Local playback: 55 passed, 0 failed, 23 skipped.
Copilot AI lite review requested due to automatic review settings September 16, 2026 21:48
@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Critical request-payload coverage and generated-model support issues remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds TargetVMSecurityOption support for Secure Boot and Trusted Launch in local server replication cmdlets.

Changes:

  • Adds validation and Generation 1 safeguards.
  • Updates cmdlet documentation and changelog.
  • Adds parameter-surface and validation tests.
File summaries
File Summary
src/Migrate/Migrate/ChangeLog.md Documents the new security option.
src/Migrate/Migrate.Autorest/test/New-AzMigrateLocalServerReplication.Tests.ps1 Tests parameter exposure and validation.
src/Migrate/Migrate.Autorest/generate-info.json Updates generation metadata.
src/Migrate/Migrate.Autorest/docs/Set-AzMigrateLocalServerReplication.md Documents the Set cmdlet parameter.
src/Migrate/Migrate.Autorest/docs/New-AzMigrateLocalServerReplication.md Documents the New cmdlet parameter.
src/Migrate/Migrate.Autorest/custom/Set-AzMigrateLocalServerReplication.ps1 Handles security option updates and validation.
src/Migrate/Migrate.Autorest/custom/New-AzMigrateLocalServerReplication.ps1 Handles security option assignment and validation.
src/Migrate/Migrate.Autorest/custom/Helper/AzLocalCommonSettings.ps1 Defines supported security option values.
Review details

Suppressed comments (5)

src/Migrate/Migrate.Autorest/custom/New-AzMigrateLocalServerReplication.ps1:81

  • This wording contradicts the implementation: None is explicitly accepted for a Generation 1 target, while only SecureBootEnabled and TrustedLaunch are rejected there. Please describe the Generation 2 restriction only for those two security-enabling values so the parameter help does not tell users that every use is Generation 2-only.
        # Specifies the security configuration of the target VM. 'SecureBootEnabled' enables Secure Boot. 'TrustedLaunch' enables Secure Boot and vTPM. Only supported for Generation 2 target VMs.

src/Migrate/Migrate.Autorest/custom/New-AzMigrateLocalServerReplication.ps1:752

  • The generated custom-properties models currently contain no SecurityOption member (the base update model exposes only InstanceType), so this assignment cannot be serialized and will fail when the new parameter is used. The generated model/interface and JSON metadata must be updated or regenerated from a schema containing securityOption; changing only the custom cmdlet layer is insufficient.
            $customProperties.SecurityOption = $TargetVMSecurityOption

src/Migrate/Migrate.Autorest/custom/Set-AzMigrateLocalServerReplication.ps1:229

  • The new Set path is likewise not exercised by the tests: the Set test file still contains only its existing live-only case, while the added tests merely inspect the command definition. This leaves both the Generation 1 validation and the customPropertiesUpdate.SecurityOption assignment unverified; add a Generation 2 playback/unit case that checks the update payload and a Generation 1 rejection case.
        if ($HasTargetVMSecurityOption) {
            if ($customProperties.HyperVGeneration -eq "1" -and
                $TargetVMSecurityOption -ne $SecurityOptions.None) {
                throw "-TargetVMSecurityOption '$TargetVMSecurityOption' requires a Generation 2 target VM. Protected item '$TargetObjectID' has a Generation 1 target VM."
            }

            $customPropertiesUpdate.SecurityOption = $TargetVMSecurityOption

src/Migrate/Migrate.Autorest/custom/Set-AzMigrateLocalServerReplication.ps1:80

  • This description has the same contradiction as the New cmdlet: the code permits -TargetVMSecurityOption None on Generation 1, so saying the option is only supported for Generation 2 is inaccurate. Restrict the Generation 2 statement to SecureBootEnabled and TrustedLaunch.
        # Specifies the security configuration of the target VM. 'SecureBootEnabled' enables Secure Boot. 'TrustedLaunch' enables Secure Boot and vTPM. Only supported for Generation 2 target VMs.

src/Migrate/Migrate/ChangeLog.md:23

  • The release note says that only Generation 2 target VMs are supported, but the new guard deliberately permits None for Generation 1 targets. Please state that only the Secure Boot/Trusted Launch values require Generation 2, otherwise users may incorrectly believe the parameter cannot be used with Generation 1 targets.
* Added 'TargetVMSecurityOption' parameter to 'New-AzMigrateLocalServerReplication' and 'Set-AzMigrateLocalServerReplication' to configure Secure Boot and Trusted Launch on the target virtual machine (VM). Supported values are 'None', 'SecureBootEnabled' and 'TrustedLaunch'; only Generation 2 target VMs are supported
  • Files reviewed: 8/8 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/Migrate/Migrate.Autorest/custom/New-AzMigrateLocalServerReplication.ps1 Outdated
Comment thread src/Migrate/Migrate.Autorest/custom/Set-AzMigrateLocalServerReplication.ps1 Outdated
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

…on the cache storage account

Initialize-AzMigrateLocalReplicationInfrastructure granted the broad Contributor role on the cache storage account to the replication vault managed identity and to the source and target appliance applications. Data-plane access already comes from Storage Blob Data Contributor, so the management role only needs to cover storage account operations such as listing keys. Narrows it to Storage Account Contributor (17d1049b-9a84-46fb-8f53-869881c3d3ab).

Existing Contributor assignments are left in place; this only changes what newly initialized infrastructure is granted. The four checks in the permission-verification retry loop move to the new role alongside the three grant sites, so the loop still converges. Fixes AB#39606529.
Copilot AI review requested due to automatic review settings September 17, 2026 21:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Add payload and Generation 1 guard tests, and correct documentation and changelog wording for the None option.

Review details

Suppressed comments (7)

Previously missed (2) — in code that hasn't changed since the last review.

src/Migrate/Migrate.Autorest/custom/New-AzMigrateLocalServerReplication.ps1:752

  • The new tests only inspect parameter metadata and ValidateSet binding; they never exercise this assignment or the Generation 1 guard. A regression that drops SecurityOption from the request (or stops rejecting non-None for Gen 1) would therefore pass. Add a mocked/playback test that invokes the cmdlet with SecureBootEnabled/TrustedLaunch and verifies the submitted custom properties, plus the Gen 1 failure path.
    src/Migrate/Migrate.Autorest/custom/Set-AzMigrateLocalServerReplication.ps1:229
  • The new tests only inspect parameter metadata and ValidateSet binding; they do not cover this update payload or the Generation 1 guard. A regression that omits SecurityOption from the Set request (or permits a non-None value for Gen 1) would pass. Add a mocked/playback test that verifies the update request and the Gen 1 failure path.

src/Migrate/Migrate.Autorest/custom/New-AzMigrateLocalServerReplication.ps1:81

  • The description says this parameter is only supported for Generation 2 targets, but None is explicitly accepted and the implementation allows it on Generation 1 ($TargetVMSecurityOption -ne $SecurityOptions.None). Please clarify that only SecureBootEnabled and TrustedLaunch require Generation 2, and regenerate the matching markdown help so users are not told that the valid None value is unsupported on Gen1.
        # Specifies the security configuration of the target VM. 'SecureBootEnabled' enables Secure Boot. 'TrustedLaunch' enables Secure Boot and vTPM. Only supported for Generation 2 target VMs.

src/Migrate/Migrate.Autorest/custom/Set-AzMigrateLocalServerReplication.ps1:80

  • The description says this parameter is only supported for Generation 2 targets, but None is explicitly accepted and the implementation allows it on Generation 1 ($TargetVMSecurityOption -ne $SecurityOptions.None). Please clarify that only SecureBootEnabled and TrustedLaunch require Generation 2, and regenerate the matching markdown help so users are not told that the valid None value is unsupported on Gen1.
        # Specifies the security configuration of the target VM. 'SecureBootEnabled' enables Secure Boot. 'TrustedLaunch' enables Secure Boot and vTPM. Only supported for Generation 2 target VMs.

src/Migrate/Migrate.Autorest/docs/New-AzMigrateLocalServerReplication.md:384

  • The guard below rejects only non-None options for Generation 1, so None is valid for Generation 1 as well. This description incorrectly says the parameter is only supported for Generation 2 and can mislead users; scope the Generation 2 restriction to SecureBootEnabled and TrustedLaunch.
### -TargetVMSecurityOption
Specifies the security configuration of the target VM.
'SecureBootEnabled' enables Secure Boot.
'TrustedLaunch' enables Secure Boot and vTPM.
Only supported for Generation 2 target VMs.

src/Migrate/Migrate.Autorest/docs/Set-AzMigrateLocalServerReplication.md:212

  • The guard below rejects only non-None options for Generation 1, so None is valid for Generation 1 as well. This description incorrectly says the parameter is only supported for Generation 2 and can mislead users; scope the Generation 2 restriction to SecureBootEnabled and TrustedLaunch.
### -TargetVMSecurityOption
Specifies the security configuration of the target VM.
'SecureBootEnabled' enables Secure Boot.
'TrustedLaunch' enables Secure Boot and vTPM.
Only supported for Generation 2 target VMs.

src/Migrate/Migrate/ChangeLog.md:23

  • The implementation permits -TargetVMSecurityOption None on Generation 1 targets, but this changelog entry says that only Generation 2 targets are supported. Please describe the restriction as applying to SecureBootEnabled and TrustedLaunch so the release note matches the actual behavior.
* Added 'TargetVMSecurityOption' parameter to 'New-AzMigrateLocalServerReplication' and 'Set-AzMigrateLocalServerReplication' to configure Secure Boot and Trusted Launch on the target virtual machine (VM). Supported values are 'None', 'SecureBootEnabled' and 'TrustedLaunch'; only Generation 2 target VMs are supported
  • Files reviewed: 9/9 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

…EnableSecureBoot

Reshapes the security surface to match the Azure Migrate portal. TargetVMSecurityOption now accepts Standard or TrustedLaunch (the user-facing security type) and a separate EnableSecureBoot controls Secure Boot. The two collapse onto the single service securityOption field, so no swagger change is needed: TrustedLaunch maps to TrustedLaunch, Standard plus Secure Boot to SecureBootEnabled, and Standard without it to None.

TrustedLaunch implies Secure Boot, so passing -EnableSecureBoot false alongside it is rejected up front, before any service lookup. The Generation 1 guard runs after the generation is derived because it needs it. -TargetVMSecurityOption Standard on its own omits the property on New so the target keeps inheriting the source, and sends SecureBootEnabled on Set so that leaving Trusted Launch drops vTPM without silently dropping Secure Boot, matching the portal.

PowerShell cannot pre-validate the no-downgrade rule: secureBootEnabled is absent from the OffAzure 2020-01-01 discovery models this module pins, and the portal reads it from 2024-12-01-preview. Requesting Standard without Secure Boot against a source that has it enabled is therefore left to the service, which rejects it with AzStackHCISecurityOptionDowngradeNotAllowed.

Local playback: 55 passed, 0 failed, 23 skipped.
Copilot AI review requested due to automatic review settings September 17, 2026 23:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Resolve the security-option contract and mapping issues, and add coverage for payload mapping and Generation 1 validation.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (2)

src/Migrate/Migrate.Autorest/custom/New-AzMigrateLocalServerReplication.ps1:784

  • When -TargetVMSecurityOption Standard is supplied without -EnableSecureBoot, this branch intentionally leaves SecurityOption unset, so the service inherits the source security setting instead of applying the requested Standard option. Since this parameter is the user-facing choice of target security type, map Standard to None (or otherwise send the corresponding wire value) whenever it is explicitly supplied.
            # Only send securityOption once a choice is expressed. '-TargetVMSecurityOption Standard'
            # on its own is not a choice about Secure Boot, so the target keeps inheriting the source.
            if ($securityType -eq $TargetVMSecurityTypes.TrustedLaunch) {
                $customProperties.SecurityOption = $SecurityOptions.TrustedLaunch
            }
            elseif ($HasEnableSecureBoot) {
                $customProperties.SecurityOption = if ($secureBootEnabled) { $SecurityOptions.SecureBootEnabled } else { $SecurityOptions.None }
            }

src/Migrate/Migrate.Autorest/custom/New-AzMigrateLocalServerReplication.ps1:783

  • The added tests verify parameter metadata and two binding-time errors, but they never exercise the new payload mapping (TrustedLaunch, SecureBootEnabled, or None) or the Generation 1 guard in either cmdlet. A regression in the code that actually assigns customProperties.SecurityOption would therefore pass these tests; add playback/unit coverage for both cmdlets and the Gen1 cases.
            if ($securityType -eq $TargetVMSecurityTypes.TrustedLaunch) {
                $customProperties.SecurityOption = $SecurityOptions.TrustedLaunch
            }
            elseif ($HasEnableSecureBoot) {
                $customProperties.SecurityOption = if ($secureBootEnabled) { $SecurityOptions.SecureBootEnabled } else { $SecurityOptions.None }
  • Files reviewed: 9/9 changed files
  • Comments generated: 2
  • Review effort level: Lite

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

New-/Set-AzMigrateLocalServerReplication now reject -EnableSecureBoot 'false' when the Gen 2 source server already has Secure Boot on, instead of letting the service fail the request with AzStackHCISecurityOptionDowngradeNotAllowed (2109019).

secureBootEnabled is absent from the OffAzure 2020-01-01 models the module is generated against, so Get-AzMigrateSourceSecureBootState reads that single field at 2024-12-01-preview via Invoke-AzRestMethod. Regenerating against a newer OffAzure version was rejected: every operationId was renamed to a *Controller_* convention after 2020-01-01 (39 of 41 gone), and only the preview carries the field for VMware as well as Hyper-V.

The check fails open - an absent field, a non-200, or a transport failure returns null and the request proceeds, leaving the service as the authority.

Error messages report the discovered display name rather than the ARM resource name, which is an opaque synthetic id for VMware sources.
Copilot AI review requested due to automatic review settings September 24, 2026 21:39

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical model incompatibility and several unresolved consistency, permission, context, documentation, and test-coverage issues remain.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 3 High severity · 2 Medium severity

Open (5)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Create and Set security option mappings differ

src/​Migrate/​Migrate.Autorest/​custom/​Set-AzMigrateLocalServerReplication.ps1:248

New-AzMigrateLocalServerReplication deliberately leaves SecurityOption unset for -TargetVMSecurityOption Standard without -EnableSecureBoot (lines 780-781), preserving source inheritance. This Set path instead forces $secureBootEnabled = $true when the same parameters are supplied, then writes SecureBootEnabled and rejects Generation 1 targets. The two cmdlets therefore give the same public input different behavior; reuse a single mapping so Standard has consistent semantics.

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

New-/Set-AzMigrateLocalServerReplication validated -TargetVMSecurityOption 'TrustedLaunch' with -EnableSecureBoot 'false' only after CheckResourceGraphModuleDependency and CheckResourcesModuleDependency had run. On agents without Az.ResourceGraph installed the cmdlet failed with a module-install message instead, so EnableSecureBoot-RejectsTrustedLaunchOptOut failed in CI while passing locally.

The contradiction is purely between two parameters and needs no Azure modules to detect, so it is now evaluated immediately after the helper imports.
Copilot AI review requested due to automatic review settings September 25, 2026 18:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Security options cannot currently be serialized reliably, New/Set semantics are inconsistent, and legacy Contributor assignments remain.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 4 High severity · 2 Medium severity

Open (6)

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

Set-AzMigrateLocalServerReplication defaults secureBootEnabled to true when -TargetVMSecurityOption is given without -EnableSecureBoot, so that leaving Trusted Launch keeps Secure Boot on a Gen 2 target the way the portal does. That default also tripped the Gen 2 guard, so asking for 'Standard' - the least restrictive option - on a Gen 1 protected item failed with a message saying Secure Boot requires Generation 2.

The guard now fires only for an explicit Trusted Launch or -EnableSecureBoot 'true' request. On Gen 1 there is no Secure Boot to inherit, so the option resolves to None. Gen 2 behaviour is unchanged, and New- was never affected because it has no inherit default.

Reported by Copilot review on PR 30152.
Copilot AI review requested due to automatic review settings September 25, 2026 19:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Resolve parameter-value mismatches, payload serialization, RBAC migration, and packaged help updates.

Review effort: Lite
Findings: 4 High severity · 2 Medium severity

Open (6)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Legacy Contributor role assignment is not removed

src/​Migrate/​Migrate.Autorest/​custom/​Initialize-AzMigrateLocalReplicationInfrastructure.ps1:806

This changes future checks and grants to Storage Account Contributor, but it never removes the existing Contributor assignment. On infrastructures initialized before this change, rerunning the cmdlet leaves the broad role in place, so the stated replacement does not reduce privileges. Add a narrowly scoped migration/removal of the old assignment, or explicitly document that this only affects new assignments.

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

…uest

The existing tests only covered parameter metadata and ValidateSet binding, so a regression that dropped the SecurityOption assignment, or sent the wrong value, would still have passed. Reported by Copilot review on PR 30152.

The service accepts securityOption on create but returns null for it on subsequent GETs, the same as migrateAsArcVM, so the value cannot be asserted by reading the protected item back. The test instead captures the outgoing PUT through -HttpPipelinePrepend and asserts the serialized body.

Tagged LiveOnly because the create path cannot be recorded: New-AzMigrateLocalServerReplication rejects an already-replicating VM using a pre-existence lookup that returns 404 on a first run, and the test recorder does not persist that exchange, so playback always concludes the VM is already in replication. This is the same limitation behind the skipped ByIdDefaultUser and ByIdPowerUser cases and the LiveOnly Set-AzMigrateLocalServerReplication suite.

Verified against a live Hyper-V source with Secure Boot enabled; the recorded request contained securityOption TrustedLaunch and the service echoed it back on create.
Copilot AI review requested due to automatic review settings September 26, 2026 00:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Moderate issues remain in security-option serialization, Standard handling, and legacy role-assignment cleanup.

Review effort: Lite
Findings: None

Resolved since last review (6)
Previously missed (4)

In code that hasn't changed since last review

Medium severity Migrate legacy Contributor assignments to least-privilege roles

src/​Migrate/​Migrate.Autorest/​custom/​Initialize-AzMigrateLocalReplicationInfrastructure.ps1:809

For cache accounts initialized by an older module version, the identities already have the old Contributor assignment at this same scope. This code only checks/adds Storage Account Contributor, so rerunning initialization leaves the broad Contributor grant in place and does not achieve the least-privilege change described in the changelog. After the replacement assignment is confirmed, remove only the module-created old role assignment (or otherwise migrate existing assignments) for the vault/source/target identities.

Medium severity Map Standard security option to the None wire value

src/​Migrate/​Migrate.Autorest/​custom/​New-AzMigrateLocalServerReplication.ps1:795

Standard is accepted by the parameter but this branch leaves SecurityOption unset; only TrustedLaunch is assigned here, so -TargetVMSecurityOption Standard silently falls back to source-inheritance instead of requesting the standard/no-security wire value. The existing migration cmdlet treats Standard as incompatible with Secure Boot (src/Migrate/Migrate.Autorest/custom/New-AzMigrateServerReplication.ps1:588-592), so assign $SecurityOptions.None when Standard is explicitly supplied (and add a request-level test).

Medium severity Do not enable Secure Boot implicitly for Standard

src/​Migrate/​Migrate.Autorest/​custom/​Set-AzMigrateLocalServerReplication.ps1:249

When -TargetVMSecurityOption Standard is supplied without -EnableSecureBoot, this condition sets $secureBootEnabled to $true. The subsequent logic therefore rejects Generation 1 targets and sends SecureBootEnabled for Generation 2 targets, making Standard behave like Secure Boot rather than the standard/no-security option. Only TrustedLaunch should force Secure Boot; leave the value false when Standard is selected without an explicit Secure Boot request.

Low severity Update PR description to match security option parameters

src/​Migrate/​Migrate/​ChangeLog.md:23

The changed user-facing contract here is Standard/TrustedLaunch, but the PR description still says TargetVMSecurityOption accepts the wire values None, SecureBootEnabled, and TrustedLaunch. Those wire values are rejected by the new ValidateSet, so please update the PR description to match the actual parameter contract (or change the implementation if the wire-value contract is intended).

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

@anhdinh-msft anhdinh-msft added this to the Az 16.5.0 (2026-11-03) milestone Sep 28, 2026
@anhdinh-msft
anhdinh-msft marked this pull request as ready for review September 29, 2026 19:57
@github-actions

Copy link
Copy Markdown

‼️ DO NOT MERGE THIS PR ‼️
This PR was labeled "Do Not Merge" because it contains code change that cannot be merged. Please contact the reviewer for more information.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants