{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/",
        "slug": "dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/"
        },
        "title": "Separate workload identity from the attestation decision that releases an asset key",
        "summary": "Does a valid cross-tenant identity token establish that a VM may receive the publisher's asset key?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:36+00:00",
        "modified_at": "2026-09-10T00:35:08+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 236,
        "potentially_affected": "Publishers evaluating Microsoft's attestation-gated Secure Key Release pattern for workloads in another party's Azure subscription.",
        "dse_recommendation": "Review identity authorization and the attestation release policy as separate decisions.",
        "primary_source": {
            "name": "Protect intellectual property on Azure VMs with attestation-gated Secure Key Release - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft&#8217;s cross-tenant asset-protection pattern keeps the vault and attestation authority with the publisher. A valid publisher-tenant identity token does not bypass the key&#8217;s attestation policy. The release gate does not itself protect an asset after decryption inside the guest; the pattern separately hardens that image. Its base design trusts the host, while optional confidential computing addresses host-memory access. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for an asset distributed into a consumer-controlled subscription, not as a generic assurance that any Trusted Launch VM conceals every secret. Identify the publisher, consumer, image owner, and accepted host threat model. Check the complete pattern and supported components before implementation.</p>\n<h2>DSE recommendation</h2>\n<p>Review identity authorization and the attestation release policy as separate decisions. Ask the asset owner to document which attested image measurements are acceptable and who may change that policy. Review the post-decryption guest controls alongside the key-release design. Do not close the security review merely because workload federation successfully obtained an identity token.</p>\n<h2>Verification</h2>\n<p>In an approved test, compare release behavior for the intended image and a deliberately nonmatching attestation condition. Preserve the decision and policy version without retaining the released key or protected asset in test logs. Examine the consumer&#8217;s remaining management and network paths separately. Record any accepted host-level risk explicitly instead of describing identity, measured boot, and confidential memory as interchangeable protections.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Attestation-gated Secure Key Release pattern</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft’s cross-tenant asset-protection pattern keeps the vault and attestation authority with the publisher. A valid publisher-tenant identity token does not bypass the key’s attestation policy. The release gate does not itself protect an asset after decryption inside the guest; the pattern separately hardens that image. Its base design trusts the host, while optional confidential computing addresses host-memory access. Microsoft Learn.\nApplicability\nUse this review for an asset distributed into a consumer-controlled subscription, not as a generic assurance that any Trusted Launch VM conceals every secret. Identify the publisher, consumer, image owner, and accepted host threat model. Check the complete pattern and supported components before implementation.\nDSE recommendation\nReview identity authorization and the attestation release policy as separate decisions. Ask the asset owner to document which attested image measurements are acceptable and who may change that policy. Review the post-decryption guest controls alongside the key-release design. Do not close the security review merely because workload federation successfully obtained an identity token.\nVerification\nIn an approved test, compare release behavior for the intended image and a deliberately nonmatching attestation condition. Preserve the decision and policy version without retaining the released key or protected asset in test logs. Examine the consumer’s remaining management and network paths separately. Record any accepted host-level risk explicitly instead of describing identity, measured boot, and confidential memory as interchangeable protections.\nOfficial references\nMicrosoft Learn: Attestation-gated Secure Key Release pattern. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft’s cross-tenant asset-protection pattern keeps the vault and attestation authority with the publisher. A valid publisher-tenant identity token does not bypass the key’s attestation policy. The release gate does not itself protect an asset after decryption inside the guest; the pattern separately hardens that image. Its base design trusts the host, while optional confidential computing addresses host-memory access. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch).\n\n## Applicability\n\nUse this review for an asset distributed into a consumer-controlled subscription, not as a generic assurance that any Trusted Launch VM conceals every secret. Identify the publisher, consumer, image owner, and accepted host threat model. Check the complete pattern and supported components before implementation.\n\n## DSE recommendation\n\nReview identity authorization and the attestation release policy as separate decisions. Ask the asset owner to document which attested image measurements are acceptable and who may change that policy. Review the post-decryption guest controls alongside the key-release design. Do not close the security review merely because workload federation successfully obtained an identity token.\n\n## Verification\n\nIn an approved test, compare release behavior for the intended image and a deliberately nonmatching attestation condition. Preserve the decision and policy version without retaining the released key or protected asset in test logs. Examine the consumer’s remaining management and network paths separately. Record any accepted host-level risk explicitly instead of describing identity, measured boot, and confidential memory as interchangeable protections.\n\n## Official references\n\n[Microsoft Learn: Attestation-gated Secure Key Release pattern](https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate workload identity from the attestation decision that releases an asset key",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/",
                "headline": "Separate workload identity from the attestation decision that releases an asset key",
                "description": "Does a valid cross-tenant identity token establish that a VM may receive the publisher's asset key?",
                "abstract": "Does a valid cross-tenant identity token establish that a VM may receive the publisher's asset key?",
                "articleBody": "Source facts\nMicrosoft’s cross-tenant asset-protection pattern keeps the vault and attestation authority with the publisher. A valid publisher-tenant identity token does not bypass the key’s attestation policy. The release gate does not itself protect an asset after decryption inside the guest; the pattern separately hardens that image. Its base design trusts the host, while optional confidential computing addresses host-memory access. Microsoft Learn.\nApplicability\nUse this review for an asset distributed into a consumer-controlled subscription, not as a generic assurance that any Trusted Launch VM conceals every secret. Identify the publisher, consumer, image owner, and accepted host threat model. Check the complete pattern and supported components before implementation.\nDSE recommendation\nReview identity authorization and the attestation release policy as separate decisions. Ask the asset owner to document which attested image measurements are acceptable and who may change that policy. Review the post-decryption guest controls alongside the key-release design. Do not close the security review merely because workload federation successfully obtained an identity token.\nVerification\nIn an approved test, compare release behavior for the intended image and a deliberately nonmatching attestation condition. Preserve the decision and policy version without retaining the released key or protected asset in test logs. Examine the consumer’s remaining management and network paths separately. Record any accepted host-level risk explicitly instead of describing identity, measured boot, and confidential memory as interchangeable protections.\nOfficial references\nMicrosoft Learn: Attestation-gated Secure Key Release pattern. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:36+00:00",
                "dateModified": "2026-09-10T00:35:08+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate workload identity from the attestation decision that releases an asset key"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 236,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Protect intellectual property on Azure VMs with attestation-gated Secure Key Release - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch"
                }
            }
        ]
    }
}