# Bind shielding data to the template disks a tenant actually trusts

> What should a tenant verify before producing a shielding-data file?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:06+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What should a tenant verify before producing a shielding-data file?

## Potentially affected

Use this review when a tenant prepares shielding data on that separate trusted computer.

## DSE recommendation

Review the template catalog separately from the answer-file settings.

## Article

## Source facts

A shielding-data file is encrypted and contains sensitive VM-provisioning information supplied by its owner. Microsoft requires a template disk before the file is created. Microsoft directs preparation to a separate trusted computer outside the guarded fabric. An answer file specializes the generalized template for the intended VM. A volume signature catalog identifies trusted template disks. During deployment, provisioning fails if the template matches none of the signatures included in the shielding data. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data).

## Applicability

Use this review when a tenant prepares shielding data on that separate trusted computer. Identify the approved template, intended VM role, and owner of the provisioning information. Keep sensitive contents out of ordinary review tickets and shared logs.

## DSE recommendation

Review the template catalog separately from the answer-file settings. Have the VM owner confirm that the signatures represent only the approved templates and that the intended role is correctly described. Record artifact identities and authorized custodians without reproducing secrets. Establish how a changed template will be approved and reflected in a newly reviewed provisioning artifact.

## Verification

Provision an approved test VM using the selected template and shielding data. Confirm its intended role and management access. In a controlled negative test, use an unapproved template and inspect the provisioning result. Retain the artifact identifiers and outcomes together so a successful deployment is tied to the actual trusted template set.

## Official references

[Microsoft Learn: Shielded VMs for tenants – Creating shielding data to define a shielded VM](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data). Source reviewed September 8, 2026.

## Primary reference

- Name: Shielded VMs for tenants - Creating shielding data to define a shielded VM
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tenant-creates-shielding-data
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Bind shielding data to the template disks a tenant actually trusts,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-065-bind-shielding-data-to-the-template-disks-a-tenant-actually-trusts/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
