# Azure Instance Metadata Service trust provider

> This page describes the steps required to configure the Azure Instance Metadata Service Trust Provider.

#

The Azure Instance Metadata Service Trust Provider supports attestation of Client Workloads and Agent Controller identities in an [Azure](https://azure.microsoft.com/) environment.

The Azure Instance Metadata Service Trust Provider relies on the [Azure Instance Metadata Service (IMDS)](https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=linux) to retrieve an instance identity document.

## Match rules

The following match rules are available for this Trust Provider type:

* sku
* subscriptionId
* vmId

Please refer to the [Azure documentation](https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=linux#attested-data) for a detailed description of match rule fields available in the identity document.