Events
Apr 29, 2 PM - Apr 30, 7 PM
Join the ultimate Windows Server virtual event April 29-30 for deep-dive technical sessions and live Q&A with Microsoft engineers.
Sign up nowThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
This article provides an overview of deploying Hyper-V guarded hosts and shielded virtual machines in a System Center Virtual Machine Manager (VMM) compute fabric.
Guarded fabrics provide additional protections for VMs to prevent tampering and theft by malicious administrators and malware. As a cloud service provider or private cloud administrator, you can deploy a guarded fabric that typically consists of a server running the Host Guardian Service (HGS), one or more guarded Hyper-V host servers, and one or more shielded VMs running on those hosts. Learn more about guarded fabrics.
Virtual machines contain sensitive data and configuration that the VM owner would not want a fabric administrator to see. However, since all the data for VMs are stored in files, the data can easily be copied off and inspected by malware or a malicious administrator.
Shielded VMs in Windows Server help prevent such attacks by rigorously attesting to the health of a Hyper-V host before booting up a VM, ensuring the VM can only be started in datacenters authorized by the VM owner, and enabling the guest OS to encrypt its own data by using a new, virtual TPM. The VM owner can select from the following two types of protection when creating a security-sensitive VM:
The core guarded fabric infrastructure (consisting of one or more guarded Hyper-V hosts, the Host Guardian Service, and the artifacts needed to create shielded VMs) is included with Windows Server 2016 and later and must be configured according to the guarded fabric documentation. Once set up, you can optionally use System Center Virtual Machine Manager to simplify management of the guarded fabric.
The core guarded fabric infrastructure (consisting of one or more guarded Hyper-V hosts, the Host Guardian Service, and the artifacts needed to create shielded VMs) is included with applicable Windows Server version and must be configured according to the guarded fabric documentation. Once set up, you can optionally use System Center Virtual Machine Manager to simplify management of the guarded fabric.
VMM can be used to:
Events
Apr 29, 2 PM - Apr 30, 7 PM
Join the ultimate Windows Server virtual event April 29-30 for deep-dive technical sessions and live Q&A with Microsoft engineers.
Sign up nowTraining
Certification
Microsoft Certified: Azure Virtual Desktop Specialty - Certifications
Plan, deliver, manage, and monitor virtual desktop experiences and remote apps on Microsoft Azure for any device.
Documentation
Learn more about: Prerequisites for guarded hosts
Create a Windows shielded VM template disk
Learn more about: Create a Windows shielded VM template disk
Guarded Fabric and Shielded VMs overview
Learn more about: Guarded fabric and shielded VMs overview