Intel® Trust Domain Extensions (Intel® TDX) is Intel’s hardware-based confidential virtual machine (CVM) technology that isolates guest VMs from the hypervisor, host OS, and other VMs. Intel positions TDX as the successor to enclave-based approaches (e.g., Intel® SGX) for cloud-scale confidential computing.
(Codename: Sapphire Rapids)
(Codename: Emerald Rapids)
(Ice Lake and older)
Intel explicitly distinguishes these generations from later TDX-capable platforms [intel.com]
Intel® TDX depends on architectural capabilities introduced starting with Sapphire Rapids, including:
Earlier Xeon generations lack the required hardware support and cannot gain TDX through firmware or microcode updates [intel.com]
| Intel® Xeon® Family | Codename / Branding | Intel® TDX Support |
| Intel® Xeon® 6+ | Xeon 6+ | Confidential computing lineage (TDX implied, not SKU‑explicit) |
| Intel® Xeon® 6 | Xeon 6 | Confidential computing lineage (TDX implied, not SKU‑explicit) |
| 5th Gen Xeon Scalable | Emerald Rapids | Yes |
| 4th Gen Xeon Scalable | Sapphire Rapids | Yes (first supported) |
| Xeon CPU Max Series | Sapphire Rapids HBM | Yes |
| 3rd Gen Xeon Scalable | Ice Lake | No |
| Earlier Xeon families | — | No |
For a complete list of processors compatible with Intel® TDX, visit:
| Note | Check the detailed Product Specification available at Intel® Product Specifications. |
For more details about Intel® TDX technology, visit Intel® TDX Platform Enablement And Validation Requirements (check permissions: CNDA Accounts).