# Assign ownership for Device Health Attestation reports

> What does a Device Health Attestation report cover, and who should interpret it?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:59+00:00
- Modified: 2026-09-08T18:17:13+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

What does a Device Health Attestation report cover, and who should interpret it?

## Potentially affected

Use this review when evaluating a DHA reporting arrangement.

## DSE recommendation

Define who operates the attestation service and who decides what a returned report means for device access.

## Article

## Source facts

Microsoft documents an on-premises Device Health Attestation server role beginning with Windows Server 2016. The DHA service validates a device’s TPM and PCR logs and issues an attestation report. The cloud-service description explains that the report represents how the device started, using TPM-protected data, and is delivered to the requesting MDM server over a protected channel. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation).

## Applicability

Use this review when evaluating a DHA reporting arrangement. Identify whether the proposed service is hosted locally or in the cloud, the requesting management system, and the applicable device requirements in the current source.

## DSE recommendation

Define who operates the attestation service and who decides what a returned report means for device access. Write down the fields that matter to that decision and how a missing report will be handled. Keep the device identity and report time with each reviewed result. Obtain a separate policy decision before turning an observed attestation result into an access restriction.

## Verification

Use an approved test device to follow a request through report receipt and administrative review. Check that the report belongs to the intended device and observation. Exercise the agreed missing-report handling and record the outcome. Retain any uncertainty about the service configuration or interpretation for the responsible management-system owner.

## Official references

[Microsoft Learn: Device Health Attestation](https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation). Source reviewed September 8, 2026.

## Primary reference

- Name: Device Health Attestation
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/device-health-attestation
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Assign ownership for Device Health Attestation reports,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-012-assign-ownership-for-device-health-attestation-reports/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
