{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/",
        "slug": "dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/"
        },
        "title": "Check the attestation version before registering a host TPM with HGS",
        "summary": "Which TPM certificate requirement applies when registering a guarded host with HGS?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:35+00:00",
        "modified_at": "2026-09-08T18:20:22+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 210,
        "potentially_affected": "Administrators preparing TPM-mode attestation evidence for Host Guardian Service.",
        "dse_recommendation": "Create a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version.",
        "primary_source": {
            "name": "Capture TPM-mode information required by HGS",
            "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft states that the v2 attestation method introduced in Windows Server 2019 requires a TPM certificate when adding a host’s endorsement-key public identifier to HGS. The Force option used with the earlier method does not bypass that requirement in v2. The source documents explicitly selecting v1 when registration without a certificate is necessary. Before collection, the host TPM must be initialized and have ownership established; Microsoft describes checking that state with the TPM console or Get-Tpm. <a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the HGS version, intended attestation policy, host hardware class, and TPM readiness. Review the policy implications of any exception before selecting a legacy attestation method.</p>\n<h2>DSE recommendation</h2>\n<p>Create a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version. Have the guarded-fabric owner review exceptions individually. Keep this enrollment decision separate from the protection and recovery of virtual-machine keys.</p>\n<h2>Verification</h2>\n<p>Perform registration for a representative host under the approved policy and preserve the selected attestation version and resulting status. Investigate certificate or readiness failures without silently changing the method. Repeat collection for each relevant hardware class and verify that a record from one host has not been reused for another.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Capture TPM-mode information required by HGS</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft states that the v2 attestation method introduced in Windows Server 2019 requires a TPM certificate when adding a host’s endorsement-key public identifier to HGS. The Force option used with the earlier method does not bypass that requirement in v2. The source documents explicitly selecting v1 when registration without a certificate is necessary. Before collection, the host TPM must be initialized and have ownership established; Microsoft describes checking that state with the TPM console or Get-Tpm. Microsoft documentation.\nApplicability\nIdentify the HGS version, intended attestation policy, host hardware class, and TPM readiness. Review the policy implications of any exception before selecting a legacy attestation method.\nDSE recommendation\nCreate a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version. Have the guarded-fabric owner review exceptions individually. Keep this enrollment decision separate from the protection and recovery of virtual-machine keys.\nVerification\nPerform registration for a representative host under the approved policy and preserve the selected attestation version and resulting status. Investigate certificate or readiness failures without silently changing the method. Repeat collection for each relevant hardware class and verify that a record from one host has not been reused for another.\nOfficial references\nMicrosoft Learn: Capture TPM-mode information required by HGS. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft states that the v2 attestation method introduced in Windows Server 2019 requires a TPM certificate when adding a host’s endorsement-key public identifier to HGS. The Force option used with the earlier method does not bypass that requirement in v2. The source documents explicitly selecting v1 when registration without a certificate is necessary. Before collection, the host TPM must be initialized and have ownership established; Microsoft describes checking that state with the TPM console or Get-Tpm. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware).\n\n## Applicability\n\nIdentify the HGS version, intended attestation policy, host hardware class, and TPM readiness. Review the policy implications of any exception before selecting a legacy attestation method.\n\n## DSE recommendation\n\nCreate a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version. Have the guarded-fabric owner review exceptions individually. Keep this enrollment decision separate from the protection and recovery of virtual-machine keys.\n\n## Verification\n\nPerform registration for a representative host under the approved policy and preserve the selected attestation version and resulting status. Investigate certificate or readiness failures without silently changing the method. Repeat collection for each relevant hardware class and verify that a record from one host has not been reused for another.\n\n## Official references\n\n[Microsoft Learn: Capture TPM-mode information required by HGS](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check the attestation version before registering a host TPM with HGS",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/",
                "headline": "Check the attestation version before registering a host TPM with HGS",
                "description": "Which TPM certificate requirement applies when registering a guarded host with HGS?",
                "abstract": "Which TPM certificate requirement applies when registering a guarded host with HGS?",
                "articleBody": "Source facts\nMicrosoft states that the v2 attestation method introduced in Windows Server 2019 requires a TPM certificate when adding a host’s endorsement-key public identifier to HGS. The Force option used with the earlier method does not bypass that requirement in v2. The source documents explicitly selecting v1 when registration without a certificate is necessary. Before collection, the host TPM must be initialized and have ownership established; Microsoft describes checking that state with the TPM console or Get-Tpm. Microsoft documentation.\nApplicability\nIdentify the HGS version, intended attestation policy, host hardware class, and TPM readiness. Review the policy implications of any exception before selecting a legacy attestation method.\nDSE recommendation\nCreate a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version. Have the guarded-fabric owner review exceptions individually. Keep this enrollment decision separate from the protection and recovery of virtual-machine keys.\nVerification\nPerform registration for a representative host under the approved policy and preserve the selected attestation version and resulting status. Investigate certificate or readiness failures without silently changing the method. Repeat collection for each relevant hardware class and verify that a record from one host has not been reused for another.\nOfficial references\nMicrosoft Learn: Capture TPM-mode information required by HGS. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:35+00:00",
                "dateModified": "2026-09-08T18:20:22+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check the attestation version before registering a host TPM with HGS"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 210,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Capture TPM-mode information required by HGS",
                    "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware"
                }
            }
        ]
    }
}