# Check the attestation version before registering a host TPM with HGS

> Which TPM certificate requirement applies when registering a guarded host with HGS?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:35+00:00
- Modified: 2026-09-08T18:20:22+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which TPM certificate requirement applies when registering a guarded host with HGS?

## Potentially affected

Administrators preparing TPM-mode attestation evidence for Host Guardian Service.

## DSE recommendation

Create a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version.

## Article

## Source facts

Microsoft states that the v2 attestation method introduced in Windows Server 2019 requires a TPM certificate when adding a host’s endorsement-key public identifier to HGS. The Force option used with the earlier method does not bypass that requirement in v2. The source documents explicitly selecting v1 when registration without a certificate is necessary. Before collection, the host TPM must be initialized and have ownership established; Microsoft describes checking that state with the TPM console or Get-Tpm. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware).

## Applicability

Identify the HGS version, intended attestation policy, host hardware class, and TPM readiness. Review the policy implications of any exception before selecting a legacy attestation method.

## DSE recommendation

Create a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version. Have the guarded-fabric owner review exceptions individually. Keep this enrollment decision separate from the protection and recovery of virtual-machine keys.

## Verification

Perform registration for a representative host under the approved policy and preserve the selected attestation version and resulting status. Investigate certificate or readiness failures without silently changing the method. Repeat collection for each relevant hardware class and verify that a record from one host has not been reused for another.

## Official references

[Microsoft Learn: Capture TPM-mode information required by HGS](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware). Source reviewed September 8, 2026.

## Primary reference

- Name: Capture TPM-mode information required by HGS
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-tpm-trusted-attestation-capturing-hardware
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check the attestation version before registering a host TPM with HGS,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-096-check-the-attestation-version-before-registering-a-host-tpm-with-hgs/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
