The XMPU is configurable either one-time or through TrustZone access from a secure master (PMU, APU TrustZone secure master, or RPU when configured as secure master). At boot time, the FSBL configures the XMPU and its configuration can be locked such that it can only be reconfigured at next power-on reset. If the configuration is not locked, then XMPU can be reconfigured any number of times by secure master accesses. If you choose to configure the XMPU dynamically, you must also consider many aspects including the idling of active devices and the AXI bus.

For more information on using the XMPU please see Isolation Methods in Zynq UltraScale+ MPSoCs (XAPP1320).