# Prepare the restart and feature checks for a Secured-core server change

> What should accompany enabling Secured-core features through Windows Admin Center?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:17:00+00:00
- Modified: 2026-09-08T18:17:13+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

What should accompany enabling Secured-core features through Windows Admin Center?

## Potentially affected

Use this review when planning a Secured-core configuration change on Windows Server.

## DSE recommendation

Have the server and hardware owners jointly review readiness.

## Article

## Source facts

Secured-core combines security capabilities across hardware, firmware, drivers, and the operating system. Microsoft lists requirements including Secure Boot, TPM 2.0, relevant firmware protections, and processor virtualization capabilities. In Windows Admin Center, the documented workflow enables unconfigured security features and schedules a restart to retain the changes. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server).

## Applicability

Use this review when planning a Secured-core configuration change on Windows Server. Check the exact hardware and firmware prerequisites in the current documentation. Identify the server workload and its permitted restart window before enabling features.

## DSE recommendation

Have the server and hardware owners jointly review readiness. Record which features are already configured and which will change, including any prerequisite that remains unresolved. Coordinate the restart with the workload owner and preserve a supported recovery route. Pilot the change on an appropriate representative server, with named reviewers for hardware status and application acceptance.

## Verification

After the planned restart, compare feature states with the approved change record. Examine reported device problems and test the workload functions selected in advance. Record the actual restart and acceptance times. Treat a feature that remains unconfigured or a workload failure as an open result requiring investigation before expanding the rollout.

## Official references

[Microsoft Learn: Configure Secured-core server for Windows Server](https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure Secured-core server for Windows Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/configure-secured-core-server
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Prepare the restart and feature checks for a Secured-core server change,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-011-prepare-the-restart-and-feature-checks-for-a-secured-core-server-change/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
