Separate shielded-VM provisioning completion from guest specialization

Which provisioning and specialization results should be checked after running New-ShieldedVM?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Which provisioning and specialization results should be checked after running New-ShieldedVM?

Potentially affected

Administrators provisioning shielded VMs with the documented Guarded Fabric Tools workflow.

DSE recommendation

Have the fabric operator record the exact provisioning invocation and sanitized specialization inputs.

Source facts

Microsoft’s guarded-host procedure installs Guarded Fabric Tools, which supplies New-ShieldedVM. The command can receive replacement specialization values when the shielding-data answer file defines them. Operating-system specialization follows VM provisioning. For a Windows Server 2016 host, Microsoft describes VM shutdown as a provisioning-completion signal and Hyper-V logs as the place to inspect unsuccessful provisioning. Microsoft documentation.

Applicability

Begin with approved template and shielding-data artifacts already prepared. Identify the guarded-host release, guest OS, intended specialization values, and supported module workflow before interpreting any completion signal.

DSE recommendation

Have the fabric operator record the exact provisioning invocation and sanitized specialization inputs. Define separate acceptance checks for the provisioning task and the guest’s subsequent setup. Agree with the tenant on the expected guest identity and how failed provisioning evidence will be preserved.

Verification

Run the approved provisioning operation and inspect its result and applicable Hyper-V events. Then verify the guest’s specialization and authorized management access independently. Record a completed task with an unfinished or failed guest setup as incomplete delivery, and resolve that discrepancy before repeating the workflow for additional VMs.

Official references

Microsoft Learn: Create a shielded VM using PowerShell. Source reviewed September 8, 2026.

Primary reference

Review the official source

Create a shielded VM using PowerShell · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE