{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/",
        "slug": "dse-20260908-012-assign-ownership-for-device-health-attestation-reports",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/"
        },
        "title": "Assign ownership for Device Health Attestation reports",
        "summary": "What does a Device Health Attestation report cover, and who should interpret it?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:16:59+00:00",
        "modified_at": "2026-09-08T18:17:13+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 216,
        "potentially_affected": "Use this review when evaluating a DHA reporting arrangement.",
        "dse_recommendation": "Define who operates the attestation service and who decides what a returned report means for device access.",
        "primary_source": {
            "name": "Device Health Attestation",
            "url": "https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents an on-premises Device Health Attestation server role beginning with Windows Server 2016. The DHA service validates a device&#8217;s TPM and PCR logs and issues an attestation report. The cloud-service description explains that the report represents how the device started, using TPM-protected data, and is delivered to the requesting MDM server over a protected channel. <a href=\"https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when evaluating a DHA reporting arrangement. Identify whether the proposed service is hosted locally or in the cloud, the requesting management system, and the applicable device requirements in the current source.</p>\n<h2>DSE recommendation</h2>\n<p>Define who operates the attestation service and who decides what a returned report means for device access. Write down the fields that matter to that decision and how a missing report will be handled. Keep the device identity and report time with each reviewed result. Obtain a separate policy decision before turning an observed attestation result into an access restriction.</p>\n<h2>Verification</h2>\n<p>Use an approved test device to follow a request through report receipt and administrative review. Check that the report belongs to the intended device and observation. Exercise the agreed missing-report handling and record the outcome. Retain any uncertainty about the service configuration or interpretation for the responsible management-system owner.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Device Health Attestation</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft documents an on-premises Device Health Attestation server role beginning with Windows Server 2016. The DHA service validates a device’s TPM and PCR logs and issues an attestation report. The cloud-service description explains that the report represents how the device started, using TPM-protected data, and is delivered to the requesting MDM server over a protected channel. Microsoft documentation.\nApplicability\nUse this review when evaluating a DHA reporting arrangement. Identify whether the proposed service is hosted locally or in the cloud, the requesting management system, and the applicable device requirements in the current source.\nDSE recommendation\nDefine who operates the attestation service and who decides what a returned report means for device access. Write down the fields that matter to that decision and how a missing report will be handled. Keep the device identity and report time with each reviewed result. Obtain a separate policy decision before turning an observed attestation result into an access restriction.\nVerification\nUse an approved test device to follow a request through report receipt and administrative review. Check that the report belongs to the intended device and observation. Exercise the agreed missing-report handling and record the outcome. Retain any uncertainty about the service configuration or interpretation for the responsible management-system owner.\nOfficial references\nMicrosoft Learn: Device Health Attestation. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft documents an on-premises Device Health Attestation server role beginning with Windows Server 2016. The DHA service validates a device’s TPM and PCR logs and issues an attestation report. The cloud-service description explains that the report represents how the device started, using TPM-protected data, and is delivered to the requesting MDM server over a protected channel. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation).\n\n## Applicability\n\nUse this review when evaluating a DHA reporting arrangement. Identify whether the proposed service is hosted locally or in the cloud, the requesting management system, and the applicable device requirements in the current source.\n\n## DSE recommendation\n\nDefine who operates the attestation service and who decides what a returned report means for device access. Write down the fields that matter to that decision and how a missing report will be handled. Keep the device identity and report time with each reviewed result. Obtain a separate policy decision before turning an observed attestation result into an access restriction.\n\n## Verification\n\nUse an approved test device to follow a request through report receipt and administrative review. Check that the report belongs to the intended device and observation. Exercise the agreed missing-report handling and record the outcome. Retain any uncertainty about the service configuration or interpretation for the responsible management-system owner.\n\n## Official references\n\n[Microsoft Learn: Device Health Attestation](https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Assign ownership for Device Health Attestation reports",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/",
                "headline": "Assign ownership for Device Health Attestation reports",
                "description": "What does a Device Health Attestation report cover, and who should interpret it?",
                "abstract": "What does a Device Health Attestation report cover, and who should interpret it?",
                "articleBody": "Source facts\nMicrosoft documents an on-premises Device Health Attestation server role beginning with Windows Server 2016. The DHA service validates a device’s TPM and PCR logs and issues an attestation report. The cloud-service description explains that the report represents how the device started, using TPM-protected data, and is delivered to the requesting MDM server over a protected channel. Microsoft documentation.\nApplicability\nUse this review when evaluating a DHA reporting arrangement. Identify whether the proposed service is hosted locally or in the cloud, the requesting management system, and the applicable device requirements in the current source.\nDSE recommendation\nDefine who operates the attestation service and who decides what a returned report means for device access. Write down the fields that matter to that decision and how a missing report will be handled. Keep the device identity and report time with each reviewed result. Obtain a separate policy decision before turning an observed attestation result into an access restriction.\nVerification\nUse an approved test device to follow a request through report receipt and administrative review. Check that the report belongs to the intended device and observation. Exercise the agreed missing-report handling and record the outcome. Retain any uncertainty about the service configuration or interpretation for the responsible management-system owner.\nOfficial references\nMicrosoft Learn: Device Health Attestation. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:16:59+00:00",
                "dateModified": "2026-09-08T18:17:13+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Assign ownership for Device Health Attestation reports"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 216,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Device Health Attestation",
                    "url": "https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation"
                }
            }
        ]
    }
}