GuideInformationBusiness ContinuityIT

Bind shielding data to the template disks a tenant actually trusts

What should a tenant verify before producing a shielding-data file?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

What should a tenant verify before producing a shielding-data file?

Potentially affected

Use this review when a tenant prepares shielding data on that separate trusted computer.

DSE recommendation

Review the template catalog separately from the answer-file settings.

Source facts

A shielding-data file is encrypted and contains sensitive VM-provisioning information supplied by its owner. Microsoft requires a template disk before the file is created. Microsoft directs preparation to a separate trusted computer outside the guarded fabric. An answer file specializes the generalized template for the intended VM. A volume signature catalog identifies trusted template disks. During deployment, provisioning fails if the template matches none of the signatures included in the shielding data. Microsoft documentation.

Applicability

Use this review when a tenant prepares shielding data on that separate trusted computer. Identify the approved template, intended VM role, and owner of the provisioning information. Keep sensitive contents out of ordinary review tickets and shared logs.

DSE recommendation

Review the template catalog separately from the answer-file settings. Have the VM owner confirm that the signatures represent only the approved templates and that the intended role is correctly described. Record artifact identities and authorized custodians without reproducing secrets. Establish how a changed template will be approved and reflected in a newly reviewed provisioning artifact.

Verification

Provision an approved test VM using the selected template and shielding data. Confirm its intended role and management access. In a controlled negative test, use an unapproved template and inspect the provisioning result. Retain the artifact identifiers and outcomes together so a successful deployment is tied to the actual trusted template set.

Official references

Microsoft Learn: Shielded VMs for tenants – Creating shielding data to define a shielded VM. Source reviewed September 8, 2026.

Primary reference

Review the official source

Shielded VMs for tenants - Creating shielding data to define a shielded VM · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE