# Prepare and sign the template disk used for shielded VM provisioning

> What makes a Windows template disk ready for shielded VM provisioning?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:55+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What makes a Windows template disk ready for shielded VM provisioning?

## Potentially affected

Use this review when producing a shielded Windows VM template.

## DSE recommendation

Have the image owner approve the guest configuration and update state before signing.

## Article

## Source facts

Microsoft begins with an operating-system VHDX that meets the stated generation-2 and shielding requirements. The source calls for current Windows updates on the template operating system because missing updates can cause the shielding process to fail. The template-disk wizard prepares the disk with BitLocker, creates its hash in a volume signature catalog, and signs that catalog with a chosen certificate for provisioning checks. The wizard changes the selected disk in place, and its protected output cannot later be edited. Microsoft suggests retaining an unprotected VHDX copy for future updates. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template).

## Applicability

Use this review when producing a shielded Windows VM template. Identify the intended guest release, image owner, signing certificate, and supported provisioning workflow. Keep the template preparation record separate from the tenant’s shielding-data artifact.

## DSE recommendation

Have the image owner approve the guest configuration and update state before signing. Preserve an approved unprotected VHDX copy before running the wizard, under the organization’s image-management controls. Record the input identity and certificate custodian without exposing private key material. Plan how later image updates will produce a newly reviewed catalog while retaining the artifact already trusted by tenants.

## Verification

Inspect the generated catalog and template identity after the approved preparation. Provision a representative shielded test VM and verify the intended guest and management behavior. Record which template and catalog were used. Resolve provisioning failures or an unexpected image identity before making the template available for additional tenant deployments.

## Official references

[Microsoft Learn: Create a Windows shielded VM template disk](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template). Source reviewed September 8, 2026.

## Primary reference

- Name: Create a Windows shielded VM template disk
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-template
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Prepare and sign the template disk used for shielded VM provisioning,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-076-prepare-and-sign-the-template-disk-used-for-shielded-vm-provisioning/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
