What you need to know
Which provisioning and specialization results should be checked after running New-ShieldedVM?
Potentially affected
Administrators provisioning shielded VMs with the documented Guarded Fabric Tools workflow.
DSE recommendation
Have the fabric operator record the exact provisioning invocation and sanitized specialization inputs.
Source facts
Microsoft’s guarded-host procedure installs Guarded Fabric Tools, which supplies New-ShieldedVM. The command can receive replacement specialization values when the shielding-data answer file defines them. Operating-system specialization follows VM provisioning. For a Windows Server 2016 host, Microsoft describes VM shutdown as a provisioning-completion signal and Hyper-V logs as the place to inspect unsuccessful provisioning. Microsoft documentation.
Applicability
Begin with approved template and shielding-data artifacts already prepared. Identify the guarded-host release, guest OS, intended specialization values, and supported module workflow before interpreting any completion signal.
DSE recommendation
Have the fabric operator record the exact provisioning invocation and sanitized specialization inputs. Define separate acceptance checks for the provisioning task and the guest’s subsequent setup. Agree with the tenant on the expected guest identity and how failed provisioning evidence will be preserved.
Verification
Run the approved provisioning operation and inspect its result and applicable Hyper-V events. Then verify the guest’s specialization and authorized management access independently. Record a completed task with an unfinished or failed guest setup as incomplete delivery, and resolve that discrepancy before repeating the workflow for additional VMs.
Official references
Microsoft Learn: Create a shielded VM using PowerShell. Source reviewed September 8, 2026.
Review the official source
Create a shielded VM using PowerShell · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE