Check the attestation version before registering a host TPM with HGS

Which TPM certificate requirement applies when registering a guarded host with HGS?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Which TPM certificate requirement applies when registering a guarded host with HGS?

Potentially affected

Administrators preparing TPM-mode attestation evidence for Host Guardian Service.

DSE recommendation

Create a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version.

Source facts

Microsoft states that the v2 attestation method introduced in Windows Server 2019 requires a TPM certificate when adding a host’s endorsement-key public identifier to HGS. The Force option used with the earlier method does not bypass that requirement in v2. The source documents explicitly selecting v1 when registration without a certificate is necessary. Before collection, the host TPM must be initialized and have ownership established; Microsoft describes checking that state with the TPM console or Get-Tpm. Microsoft documentation.

Applicability

Identify the HGS version, intended attestation policy, host hardware class, and TPM readiness. Review the policy implications of any exception before selecting a legacy attestation method.

DSE recommendation

Create a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version. Have the guarded-fabric owner review exceptions individually. Keep this enrollment decision separate from the protection and recovery of virtual-machine keys.

Verification

Perform registration for a representative host under the approved policy and preserve the selected attestation version and resulting status. Investigate certificate or readiness failures without silently changing the method. Repeat collection for each relevant hardware class and verify that a record from one host has not been reused for another.

Official references

Microsoft Learn: Capture TPM-mode information required by HGS. Source reviewed September 8, 2026.

Primary reference

Review the official source

Capture TPM-mode information required by HGS · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE