{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/",
        "slug": "dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/"
        },
        "title": "Prepare the restart and feature checks for a Secured-core server change",
        "summary": "What should accompany enabling Secured-core features through Windows Admin Center?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:17:00+00:00",
        "modified_at": "2026-09-08T18:17:13+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 207,
        "potentially_affected": "Use this review when planning a Secured-core configuration change on Windows Server.",
        "dse_recommendation": "Have the server and hardware owners jointly review readiness.",
        "primary_source": {
            "name": "Configure Secured-core server for Windows Server",
            "url": "https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Secured-core combines security capabilities across hardware, firmware, drivers, and the operating system. Microsoft lists requirements including Secure Boot, TPM 2.0, relevant firmware protections, and processor virtualization capabilities. In Windows Admin Center, the documented workflow enables unconfigured security features and schedules a restart to retain the changes. <a href=\"https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when planning a Secured-core configuration change on Windows Server. Check the exact hardware and firmware prerequisites in the current documentation. Identify the server workload and its permitted restart window before enabling features.</p>\n<h2>DSE recommendation</h2>\n<p>Have the server and hardware owners jointly review readiness. Record which features are already configured and which will change, including any prerequisite that remains unresolved. Coordinate the restart with the workload owner and preserve a supported recovery route. Pilot the change on an appropriate representative server, with named reviewers for hardware status and application acceptance.</p>\n<h2>Verification</h2>\n<p>After the planned restart, compare feature states with the approved change record. Examine reported device problems and test the workload functions selected in advance. Record the actual restart and acceptance times. Treat a feature that remains unconfigured or a workload failure as an open result requiring investigation before expanding the rollout.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Secured-core server for Windows Server</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nSecured-core combines security capabilities across hardware, firmware, drivers, and the operating system. Microsoft lists requirements including Secure Boot, TPM 2.0, relevant firmware protections, and processor virtualization capabilities. In Windows Admin Center, the documented workflow enables unconfigured security features and schedules a restart to retain the changes. Microsoft documentation.\nApplicability\nUse this review when planning a Secured-core configuration change on Windows Server. Check the exact hardware and firmware prerequisites in the current documentation. Identify the server workload and its permitted restart window before enabling features.\nDSE recommendation\nHave the server and hardware owners jointly review readiness. Record which features are already configured and which will change, including any prerequisite that remains unresolved. Coordinate the restart with the workload owner and preserve a supported recovery route. Pilot the change on an appropriate representative server, with named reviewers for hardware status and application acceptance.\nVerification\nAfter the planned restart, compare feature states with the approved change record. Examine reported device problems and test the workload functions selected in advance. Record the actual restart and acceptance times. Treat a feature that remains unconfigured or a workload failure as an open result requiring investigation before expanding the rollout.\nOfficial references\nMicrosoft Learn: Configure Secured-core server for Windows Server. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nSecured-core combines security capabilities across hardware, firmware, drivers, and the operating system. Microsoft lists requirements including Secure Boot, TPM 2.0, relevant firmware protections, and processor virtualization capabilities. In Windows Admin Center, the documented workflow enables unconfigured security features and schedules a restart to retain the changes. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server).\n\n## Applicability\n\nUse this review when planning a Secured-core configuration change on Windows Server. Check the exact hardware and firmware prerequisites in the current documentation. Identify the server workload and its permitted restart window before enabling features.\n\n## DSE recommendation\n\nHave the server and hardware owners jointly review readiness. Record which features are already configured and which will change, including any prerequisite that remains unresolved. Coordinate the restart with the workload owner and preserve a supported recovery route. Pilot the change on an appropriate representative server, with named reviewers for hardware status and application acceptance.\n\n## Verification\n\nAfter the planned restart, compare feature states with the approved change record. Examine reported device problems and test the workload functions selected in advance. Record the actual restart and acceptance times. Treat a feature that remains unconfigured or a workload failure as an open result requiring investigation before expanding the rollout.\n\n## Official references\n\n[Microsoft Learn: Configure Secured-core server for Windows Server](https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Prepare the restart and feature checks for a Secured-core server change",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/",
                "headline": "Prepare the restart and feature checks for a Secured-core server change",
                "description": "What should accompany enabling Secured-core features through Windows Admin Center?",
                "abstract": "What should accompany enabling Secured-core features through Windows Admin Center?",
                "articleBody": "Source facts\nSecured-core combines security capabilities across hardware, firmware, drivers, and the operating system. Microsoft lists requirements including Secure Boot, TPM 2.0, relevant firmware protections, and processor virtualization capabilities. In Windows Admin Center, the documented workflow enables unconfigured security features and schedules a restart to retain the changes. Microsoft documentation.\nApplicability\nUse this review when planning a Secured-core configuration change on Windows Server. Check the exact hardware and firmware prerequisites in the current documentation. Identify the server workload and its permitted restart window before enabling features.\nDSE recommendation\nHave the server and hardware owners jointly review readiness. Record which features are already configured and which will change, including any prerequisite that remains unresolved. Coordinate the restart with the workload owner and preserve a supported recovery route. Pilot the change on an appropriate representative server, with named reviewers for hardware status and application acceptance.\nVerification\nAfter the planned restart, compare feature states with the approved change record. Examine reported device problems and test the workload functions selected in advance. Record the actual restart and acceptance times. Treat a feature that remains unconfigured or a workload failure as an open result requiring investigation before expanding the rollout.\nOfficial references\nMicrosoft Learn: Configure Secured-core server for Windows Server. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:17:00+00:00",
                "dateModified": "2026-09-08T18:17:13+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Prepare the restart and feature checks for a Secured-core server change"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 207,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Secured-core server for Windows Server",
                    "url": "https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server"
                }
            }
        ]
    }
}