If checked, instance metadata HTTP requests require a signed token header and only support IMDSv2 (the default). If disabled, both IMDSv1 and IMDSv2 requests are supported, but IMDSv2 should be used as it is a best security practice.