The plan is calculated into a PCR on the Confidential VM's vTPM (that is matched in The main element launch plan about the KMS With all the expected plan hash to the deployment) and enforced by a hardened container https://laylalsut105621.azzablog.com/30423088/anti-ransom-things-to-know-before-you-buy