What you need to know
What should be checked when a Trusted Launch VM's Guest Attestation extension fails behind network controls?
Potentially affected
Azure Trusted Launch VM operators configuring or troubleshooting Guest Attestation.
DSE recommendation
Review the attestation communication path before treating an extension-provisioning failure as a boot-integrity finding.
Source facts
Azure Trusted Launch uses guest attestation through Azure Attestation to monitor the boot sequence. Installing the attestation extensions requires both Secure Boot and vTPM. Microsoft identifies NSG or proxy configuration as a possible cause of Guest Attestation provisioning failure: the extension needs communication with the attestation endpoint. The documented NSG procedure permits outbound access using the AzureAttestation service tag. Microsoft Learn.
Applicability
Use this check for a Trusted Launch VM whose integrity-monitoring deployment or reporting needs investigation. Record its security settings and actual extension status. Distinguish the investigation of an unavailable attestation path from an assessment of the VM’s boot evidence.
DSE recommendation
Review the attestation communication path before treating an extension-provisioning failure as a boot-integrity finding. Ask the network owner to inspect the relevant outbound policy and proxy route. Propose only the narrowly scoped change justified by the documented endpoint requirement. Keep the VM security configuration, extension deployment, and network exception in the same investigation record so one team’s successful change does not close another team’s unresolved check.
Verification
After an approved correction, inspect the Guest Attestation extension’s provisioning result and the corresponding integrity-monitoring status. Confirm that the intended outbound rule applies to the tested VM and that unrelated access was not broadened. Preserve any remaining error message with the tested configuration. Require the responsible security reviewer to interpret the resulting attestation information; a successful network connection alone should not be used as the investigation’s final acceptance criterion.
Official references
Microsoft Learn: Boot integrity monitoring overview. Source reviewed September 9, 2026.
Review the official source
Boot integrity monitoring overview - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE