# Separate shielded-VM provisioning completion from guest specialization

> Which provisioning and specialization results should be checked after running New-ShieldedVM?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-133-separate-shielded-vm-provisioning-completion-from-guest-specialization/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:58+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which provisioning and specialization results should be checked after running New-ShieldedVM?

## Potentially affected

Administrators provisioning shielded VMs with the documented Guarded Fabric Tools workflow.

## DSE recommendation

Have the fabric operator record the exact provisioning invocation and sanitized specialization inputs.

## Article

## Source facts

Microsoft’s guarded-host procedure installs Guarded Fabric Tools, which supplies New-ShieldedVM. The command can receive replacement specialization values when the shielding-data answer file defines them. Operating-system specialization follows VM provisioning. For a Windows Server 2016 host, Microsoft describes VM shutdown as a provisioning-completion signal and Hyper-V logs as the place to inspect unsuccessful provisioning. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-using-powershell).

## Applicability

Begin with approved template and shielding-data artifacts already prepared. Identify the guarded-host release, guest OS, intended specialization values, and supported module workflow before interpreting any completion signal.

## DSE recommendation

Have the fabric operator record the exact provisioning invocation and sanitized specialization inputs. Define separate acceptance checks for the provisioning task and the guest’s subsequent setup. Agree with the tenant on the expected guest identity and how failed provisioning evidence will be preserved.

## Verification

Run the approved provisioning operation and inspect its result and applicable Hyper-V events. Then verify the guest’s specialization and authorized management access independently. Record a completed task with an unfinished or failed guest setup as incomplete delivery, and resolve that discrepancy before repeating the workflow for additional VMs.

## Official references

[Microsoft Learn: Create a shielded VM using PowerShell](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-using-powershell). Source reviewed September 8, 2026.

## Primary reference

- Name: Create a shielded VM using PowerShell
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-create-a-shielded-vm-using-powershell
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate shielded-VM provisioning completion from guest specialization,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-133-separate-shielded-vm-provisioning-completion-from-guest-specialization/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
