What you need to know
What certificate-renewal constraint must be preserved for Host Guardian Service?
Potentially affected
Administrators obtaining or renewing HGS signing and encryption certificates.
DSE recommendation
Prepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian.
Source facts
HGS uses signing and encryption certificates to protect the information needed to start shielded VMs. VM owners use the public certificate material to authorize the guarded environment. Microsoft recommends certificates from a trusted certification authority. The documentation also permits self-signed certificates for a lab environment. The HGS certificate requirements specify renewal with the same key. Microsoft warns that renewing with different keys prevents shielded VMs from starting. Microsoft documentation.
Applicability
Identify the certificate roles, current keys, issuing authority, expiration dates, and all HGS nodes. Review the source’s complete cryptographic requirements and the key-storage provider before ordering replacements.
DSE recommendation
Prepare a renewal plan that explicitly preserves the required keys and identifies the authorized custodian. Have the guarded-fabric owner review how renewal differs from an intentional key-change project. Schedule a representative startup test and retain the approved recovery material before replacing certificates.
Verification
Inspect the renewed certificates and confirm the intended key relationship and deployment on the required nodes. Start a representative shielded VM through the approved guarded-host path and record HGS results. Treat an unexplained key change or startup failure as unresolved before completing the renewal.
Official references
Microsoft Learn: Obtain certificates for HGS. Source reviewed September 8, 2026.
Review the official source
Obtain certificates for HGS · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE