{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/",
        "slug": "dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/"
        },
        "title": "Bind shielding data to the template disks a tenant actually trusts",
        "summary": "What should a tenant verify before producing a shielding-data file?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:16:06+00:00",
        "modified_at": "2026-09-08T18:20:22+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 245,
        "potentially_affected": "Use this review when a tenant prepares shielding data on that separate trusted computer.",
        "dse_recommendation": "Review the template catalog separately from the answer-file settings.",
        "primary_source": {
            "name": "Shielded VMs for tenants - Creating shielding data to define a shielded VM",
            "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>A shielding-data file is encrypted and contains sensitive VM-provisioning information supplied by its owner. Microsoft requires a template disk before the file is created. Microsoft directs preparation to a separate trusted computer outside the guarded fabric. An answer file specializes the generalized template for the intended VM. A volume signature catalog identifies trusted template disks. During deployment, provisioning fails if the template matches none of the signatures included in the shielding data. <a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when a tenant prepares shielding data on that separate trusted computer. Identify the approved template, intended VM role, and owner of the provisioning information. Keep sensitive contents out of ordinary review tickets and shared logs.</p>\n<h2>DSE recommendation</h2>\n<p>Review the template catalog separately from the answer-file settings. Have the VM owner confirm that the signatures represent only the approved templates and that the intended role is correctly described. Record artifact identities and authorized custodians without reproducing secrets. Establish how a changed template will be approved and reflected in a newly reviewed provisioning artifact.</p>\n<h2>Verification</h2>\n<p>Provision an approved test VM using the selected template and shielding data. Confirm its intended role and management access. In a controlled negative test, use an unapproved template and inspect the provisioning result. Retain the artifact identifiers and outcomes together so a successful deployment is tied to the actual trusted template set.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Shielded VMs for tenants &#8211; Creating shielding data to define a shielded VM</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nA shielding-data file is encrypted and contains sensitive VM-provisioning information supplied by its owner. Microsoft requires a template disk before the file is created. Microsoft directs preparation to a separate trusted computer outside the guarded fabric. An answer file specializes the generalized template for the intended VM. A volume signature catalog identifies trusted template disks. During deployment, provisioning fails if the template matches none of the signatures included in the shielding data. Microsoft documentation.\nApplicability\nUse this review when a tenant prepares shielding data on that separate trusted computer. Identify the approved template, intended VM role, and owner of the provisioning information. Keep sensitive contents out of ordinary review tickets and shared logs.\nDSE recommendation\nReview the template catalog separately from the answer-file settings. Have the VM owner confirm that the signatures represent only the approved templates and that the intended role is correctly described. Record artifact identities and authorized custodians without reproducing secrets. Establish how a changed template will be approved and reflected in a newly reviewed provisioning artifact.\nVerification\nProvision an approved test VM using the selected template and shielding data. Confirm its intended role and management access. In a controlled negative test, use an unapproved template and inspect the provisioning result. Retain the artifact identifiers and outcomes together so a successful deployment is tied to the actual trusted template set.\nOfficial references\nMicrosoft Learn: Shielded VMs for tenants – Creating shielding data to define a shielded VM. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nA shielding-data file is encrypted and contains sensitive VM-provisioning information supplied by its owner. Microsoft requires a template disk before the file is created. Microsoft directs preparation to a separate trusted computer outside the guarded fabric. An answer file specializes the generalized template for the intended VM. A volume signature catalog identifies trusted template disks. During deployment, provisioning fails if the template matches none of the signatures included in the shielding data. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data).\n\n## Applicability\n\nUse this review when a tenant prepares shielding data on that separate trusted computer. Identify the approved template, intended VM role, and owner of the provisioning information. Keep sensitive contents out of ordinary review tickets and shared logs.\n\n## DSE recommendation\n\nReview the template catalog separately from the answer-file settings. Have the VM owner confirm that the signatures represent only the approved templates and that the intended role is correctly described. Record artifact identities and authorized custodians without reproducing secrets. Establish how a changed template will be approved and reflected in a newly reviewed provisioning artifact.\n\n## Verification\n\nProvision an approved test VM using the selected template and shielding data. Confirm its intended role and management access. In a controlled negative test, use an unapproved template and inspect the provisioning result. Retain the artifact identifiers and outcomes together so a successful deployment is tied to the actual trusted template set.\n\n## Official references\n\n[Microsoft Learn: Shielded VMs for tenants – Creating shielding data to define a shielded VM](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Bind shielding data to the template disks a tenant actually trusts",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/",
                "headline": "Bind shielding data to the template disks a tenant actually trusts",
                "description": "What should a tenant verify before producing a shielding-data file?",
                "abstract": "What should a tenant verify before producing a shielding-data file?",
                "articleBody": "Source facts\nA shielding-data file is encrypted and contains sensitive VM-provisioning information supplied by its owner. Microsoft requires a template disk before the file is created. Microsoft directs preparation to a separate trusted computer outside the guarded fabric. An answer file specializes the generalized template for the intended VM. A volume signature catalog identifies trusted template disks. During deployment, provisioning fails if the template matches none of the signatures included in the shielding data. Microsoft documentation.\nApplicability\nUse this review when a tenant prepares shielding data on that separate trusted computer. Identify the approved template, intended VM role, and owner of the provisioning information. Keep sensitive contents out of ordinary review tickets and shared logs.\nDSE recommendation\nReview the template catalog separately from the answer-file settings. Have the VM owner confirm that the signatures represent only the approved templates and that the intended role is correctly described. Record artifact identities and authorized custodians without reproducing secrets. Establish how a changed template will be approved and reflected in a newly reviewed provisioning artifact.\nVerification\nProvision an approved test VM using the selected template and shielding data. Confirm its intended role and management access. In a controlled negative test, use an unapproved template and inspect the provisioning result. Retain the artifact identifiers and outcomes together so a successful deployment is tied to the actual trusted template set.\nOfficial references\nMicrosoft Learn: Shielded VMs for tenants – Creating shielding data to define a shielded VM. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:16:06+00:00",
                "dateModified": "2026-09-08T18:20:22+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Bind shielding data to the template disks a tenant actually trusts"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 245,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Shielded VMs for tenants - Creating shielding data to define a shielded VM",
                    "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data"
                }
            }
        ]
    }
}