{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/",
        "slug": "dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/"
        },
        "title": "Prepare and sign the template disk used for shielded VM provisioning",
        "summary": "What makes a Windows template disk ready for shielded VM provisioning?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:55+00:00",
        "modified_at": "2026-09-08T18:20:22+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 253,
        "potentially_affected": "Use this review when producing a shielded Windows VM template.",
        "dse_recommendation": "Have the image owner approve the guest configuration and update state before signing.",
        "primary_source": {
            "name": "Create a Windows shielded VM template disk",
            "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft begins with an operating-system VHDX that meets the stated generation-2 and shielding requirements. The source calls for current Windows updates on the template operating system because missing updates can cause the shielding process to fail. The template-disk wizard prepares the disk with BitLocker, creates its hash in a volume signature catalog, and signs that catalog with a chosen certificate for provisioning checks. The wizard changes the selected disk in place, and its protected output cannot later be edited. Microsoft suggests retaining an unprotected VHDX copy for future updates. <a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when producing a shielded Windows VM template. Identify the intended guest release, image owner, signing certificate, and supported provisioning workflow. Keep the template preparation record separate from the tenant&#8217;s shielding-data artifact.</p>\n<h2>DSE recommendation</h2>\n<p>Have the image owner approve the guest configuration and update state before signing. Preserve an approved unprotected VHDX copy before running the wizard, under the organization&#8217;s image-management controls. Record the input identity and certificate custodian without exposing private key material. Plan how later image updates will produce a newly reviewed catalog while retaining the artifact already trusted by tenants.</p>\n<h2>Verification</h2>\n<p>Inspect the generated catalog and template identity after the approved preparation. Provision a representative shielded test VM and verify the intended guest and management behavior. Record which template and catalog were used. Resolve provisioning failures or an unexpected image identity before making the template available for additional tenant deployments.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create a Windows shielded VM template disk</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft begins with an operating-system VHDX that meets the stated generation-2 and shielding requirements. The source calls for current Windows updates on the template operating system because missing updates can cause the shielding process to fail. The template-disk wizard prepares the disk with BitLocker, creates its hash in a volume signature catalog, and signs that catalog with a chosen certificate for provisioning checks. The wizard changes the selected disk in place, and its protected output cannot later be edited. Microsoft suggests retaining an unprotected VHDX copy for future updates. Microsoft documentation.\nApplicability\nUse this review when producing a shielded Windows VM template. Identify the intended guest release, image owner, signing certificate, and supported provisioning workflow. Keep the template preparation record separate from the tenant’s shielding-data artifact.\nDSE recommendation\nHave the image owner approve the guest configuration and update state before signing. Preserve an approved unprotected VHDX copy before running the wizard, under the organization’s image-management controls. Record the input identity and certificate custodian without exposing private key material. Plan how later image updates will produce a newly reviewed catalog while retaining the artifact already trusted by tenants.\nVerification\nInspect the generated catalog and template identity after the approved preparation. Provision a representative shielded test VM and verify the intended guest and management behavior. Record which template and catalog were used. Resolve provisioning failures or an unexpected image identity before making the template available for additional tenant deployments.\nOfficial references\nMicrosoft Learn: Create a Windows shielded VM template disk. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft begins with an operating-system VHDX that meets the stated generation-2 and shielding requirements. The source calls for current Windows updates on the template operating system because missing updates can cause the shielding process to fail. The template-disk wizard prepares the disk with BitLocker, creates its hash in a volume signature catalog, and signs that catalog with a chosen certificate for provisioning checks. The wizard changes the selected disk in place, and its protected output cannot later be edited. Microsoft suggests retaining an unprotected VHDX copy for future updates. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template).\n\n## Applicability\n\nUse this review when producing a shielded Windows VM template. Identify the intended guest release, image owner, signing certificate, and supported provisioning workflow. Keep the template preparation record separate from the tenant’s shielding-data artifact.\n\n## DSE recommendation\n\nHave the image owner approve the guest configuration and update state before signing. Preserve an approved unprotected VHDX copy before running the wizard, under the organization’s image-management controls. Record the input identity and certificate custodian without exposing private key material. Plan how later image updates will produce a newly reviewed catalog while retaining the artifact already trusted by tenants.\n\n## Verification\n\nInspect the generated catalog and template identity after the approved preparation. Provision a representative shielded test VM and verify the intended guest and management behavior. Record which template and catalog were used. Resolve provisioning failures or an unexpected image identity before making the template available for additional tenant deployments.\n\n## Official references\n\n[Microsoft Learn: Create a Windows shielded VM template disk](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Prepare and sign the template disk used for shielded VM provisioning",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/",
                "headline": "Prepare and sign the template disk used for shielded VM provisioning",
                "description": "What makes a Windows template disk ready for shielded VM provisioning?",
                "abstract": "What makes a Windows template disk ready for shielded VM provisioning?",
                "articleBody": "Source facts\nMicrosoft begins with an operating-system VHDX that meets the stated generation-2 and shielding requirements. The source calls for current Windows updates on the template operating system because missing updates can cause the shielding process to fail. The template-disk wizard prepares the disk with BitLocker, creates its hash in a volume signature catalog, and signs that catalog with a chosen certificate for provisioning checks. The wizard changes the selected disk in place, and its protected output cannot later be edited. Microsoft suggests retaining an unprotected VHDX copy for future updates. Microsoft documentation.\nApplicability\nUse this review when producing a shielded Windows VM template. Identify the intended guest release, image owner, signing certificate, and supported provisioning workflow. Keep the template preparation record separate from the tenant’s shielding-data artifact.\nDSE recommendation\nHave the image owner approve the guest configuration and update state before signing. Preserve an approved unprotected VHDX copy before running the wizard, under the organization’s image-management controls. Record the input identity and certificate custodian without exposing private key material. Plan how later image updates will produce a newly reviewed catalog while retaining the artifact already trusted by tenants.\nVerification\nInspect the generated catalog and template identity after the approved preparation. Provision a representative shielded test VM and verify the intended guest and management behavior. Record which template and catalog were used. Resolve provisioning failures or an unexpected image identity before making the template available for additional tenant deployments.\nOfficial references\nMicrosoft Learn: Create a Windows shielded VM template disk. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:55+00:00",
                "dateModified": "2026-09-08T18:20:22+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Prepare and sign the template disk used for shielded VM provisioning"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 253,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create a Windows shielded VM template disk",
                    "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template"
                }
            }
        ]
    }
}