What you need to know
Which TPM certificate requirement applies when registering a guarded host with HGS?
Potentially affected
Administrators preparing TPM-mode attestation evidence for Host Guardian Service.
DSE recommendation
Create a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version.
Source facts
Microsoft states that the v2 attestation method introduced in Windows Server 2019 requires a TPM certificate when adding a host’s endorsement-key public identifier to HGS. The Force option used with the earlier method does not bypass that requirement in v2. The source documents explicitly selecting v1 when registration without a certificate is necessary. Before collection, the host TPM must be initialized and have ownership established; Microsoft describes checking that state with the TPM console or Get-Tpm. Microsoft documentation.
Applicability
Identify the HGS version, intended attestation policy, host hardware class, and TPM readiness. Review the policy implications of any exception before selecting a legacy attestation method.
DSE recommendation
Create a host-registration record containing the hardware identity, TPM readiness evidence, certificate availability, and intended policy version. Have the guarded-fabric owner review exceptions individually. Keep this enrollment decision separate from the protection and recovery of virtual-machine keys.
Verification
Perform registration for a representative host under the approved policy and preserve the selected attestation version and resulting status. Investigate certificate or readiness failures without silently changing the method. Repeat collection for each relevant hardware class and verify that a record from one host has not been reused for another.
Official references
Microsoft Learn: Capture TPM-mode information required by HGS. Source reviewed September 8, 2026.
Review the official source
Capture TPM-mode information required by HGS · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE