# Include the attestation endpoint in Trusted Launch integrity-monitoring checks

> What should be checked when a Trusted Launch VM's Guest Attestation extension fails behind network controls?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-030-include-the-attestation-endpoint-in-trusted-launch-integrity-monitoring-checks/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:26+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

What should be checked when a Trusted Launch VM's Guest Attestation extension fails behind network controls?

## Potentially affected

Azure Trusted Launch VM operators configuring or troubleshooting Guest Attestation.

## DSE recommendation

Review the attestation communication path before treating an extension-provisioning failure as a boot-integrity finding.

## Article

## Source facts

Azure Trusted Launch uses guest attestation through Azure Attestation to monitor the boot sequence. Installing the attestation extensions requires both Secure Boot and vTPM. Microsoft identifies NSG or proxy configuration as a possible cause of Guest Attestation provisioning failure: the extension needs communication with the attestation endpoint. The documented NSG procedure permits outbound access using the AzureAttestation service tag. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/boot-integrity-monitoring-overview).

## Applicability

Use this check for a Trusted Launch VM whose integrity-monitoring deployment or reporting needs investigation. Record its security settings and actual extension status. Distinguish the investigation of an unavailable attestation path from an assessment of the VM’s boot evidence.

## DSE recommendation

Review the attestation communication path before treating an extension-provisioning failure as a boot-integrity finding. Ask the network owner to inspect the relevant outbound policy and proxy route. Propose only the narrowly scoped change justified by the documented endpoint requirement. Keep the VM security configuration, extension deployment, and network exception in the same investigation record so one team’s successful change does not close another team’s unresolved check.

## Verification

After an approved correction, inspect the Guest Attestation extension’s provisioning result and the corresponding integrity-monitoring status. Confirm that the intended outbound rule applies to the tested VM and that unrelated access was not broadened. Preserve any remaining error message with the tested configuration. Require the responsible security reviewer to interpret the resulting attestation information; a successful network connection alone should not be used as the investigation’s final acceptance criterion.

## Official references

[Microsoft Learn: Boot integrity monitoring overview](https://learn.microsoft.com/en-us/azure/virtual-machines/boot-integrity-monitoring-overview). Source reviewed September 9, 2026.

## Primary reference

- Name: Boot integrity monitoring overview - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/boot-integrity-monitoring-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Include the attestation endpoint in Trusted Launch integrity-monitoring checks,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-030-include-the-attestation-endpoint-in-trusted-launch-integrity-monitoring-checks/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
