# Separate workload identity from the attestation decision that releases an asset key

> Does a valid cross-tenant identity token establish that a VM may receive the publisher's asset key?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:36+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does a valid cross-tenant identity token establish that a VM may receive the publisher's asset key?

## Potentially affected

Publishers evaluating Microsoft's attestation-gated Secure Key Release pattern for workloads in another party's Azure subscription.

## DSE recommendation

Review identity authorization and the attestation release policy as separate decisions.

## Article

## Source facts

Microsoft’s cross-tenant asset-protection pattern keeps the vault and attestation authority with the publisher. A valid publisher-tenant identity token does not bypass the key’s attestation policy. The release gate does not itself protect an asset after decryption inside the guest; the pattern separately hardens that image. Its base design trusts the host, while optional confidential computing addresses host-memory access. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch).

## Applicability

Use this review for an asset distributed into a consumer-controlled subscription, not as a generic assurance that any Trusted Launch VM conceals every secret. Identify the publisher, consumer, image owner, and accepted host threat model. Check the complete pattern and supported components before implementation.

## DSE recommendation

Review identity authorization and the attestation release policy as separate decisions. Ask the asset owner to document which attested image measurements are acceptable and who may change that policy. Review the post-decryption guest controls alongside the key-release design. Do not close the security review merely because workload federation successfully obtained an identity token.

## Verification

In an approved test, compare release behavior for the intended image and a deliberately nonmatching attestation condition. Preserve the decision and policy version without retaining the released key or protected asset in test logs. Examine the consumer’s remaining management and network paths separately. Record any accepted host-level risk explicitly instead of describing identity, measured boot, and confidential memory as interchangeable protections.

## Official references

[Microsoft Learn: Attestation-gated Secure Key Release pattern](https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch). Source reviewed September 9, 2026.

## Primary reference

- Name: Protect intellectual property on Azure VMs with attestation-gated Secure Key Release - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/secure-key-release-pattern-trusted-launch
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate workload identity from the attestation decision that releases an asset key,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-080-separate-workload-identity-from-the-attestation-decision-that-releases-an-asset-key/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
