Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
powershell_heavy
windows_tools
windows_first
Summary
The documentation page shows moderate Windows bias in the advanced (customer-managed key) scenario. Several steps use PowerShell syntax and Windows-specific tools (e.g., Microsoft Graph PowerShell SDK) without providing equivalent Bash or cross-platform alternatives. PowerShell commands are interleaved with Azure CLI, and variables are set using PowerShell syntax, which may not work for Linux/macOS users. The initial sections are cross-platform, but the advanced scenario assumes a Windows/PowerShell environment. Linux parity is restored in the attestation section, which is Linux-focused.
Recommendations
  • For every PowerShell command, provide a Bash (or cross-platform) equivalent, especially for variable assignment and Azure CLI invocations.
  • Clearly separate Windows/PowerShell and Linux/Bash instructions, or provide tabs for both environments.
  • For steps requiring Microsoft Graph, provide REST API or Azure CLI alternatives, or link to platform-agnostic instructions.
  • Avoid using PowerShell-specific constructs (e.g., Out-String, ConvertFrom-Json, $var assignment) in mainline CLI documentation unless alternatives are shown.
  • Review the order of examples to ensure neither Windows nor Linux is prioritized without justification.
  • Add a note at the start of advanced sections clarifying which OS/shell the instructions target, and link to equivalents for other platforms.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Biased Biased
2026-01-10 00:00 #92 completed Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-29 18:00 #48 cancelled Biased Biased
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean

Flagged Code Snippets

Make a note of the `publicIpAddress` to use later.

## Create Confidential virtual machine using a Customer Managed Key

To create a confidential [disk encryption set](/azure/virtual-machines/linux/disks-enable-customer-managed-keys-cli), you have two options: Using [Azure Key Vault](/azure/key-vault/general/quick-create-cli) or [Azure Key Vault managed Hardware Security Module (HSM)](/azure/key-vault/managed-hsm/quick-create-cli). Based on your security and compliance needs you can choose either option. However, it is important to note that the standard SKU is not supported. The following example uses Azure Key Vault Premium.

1. Grant confidential VM Service Principal `Confidential VM Orchestrator` to tenant.
For this step you need to be a Global Admin or you need to have the User Access Administrator RBAC role. [Install Microsoft Graph SDK](/powershell/microsoftgraph/installation) to execute the commands below.