Secure Hyper-V workloads

Intermediate
Administrator
Security Engineer
Solution Architect
Windows Server

This module covers how to secure Hyper-V workloads in Windows Server using guarded fabric. You learn how to deploy and configure the Host Guardian Service (HGS) with TPM-trusted and Host Key attestation modes, use the Key Protection Service (KPS) to control access to shielded VM encryption keys, distinguish between standard VMs, encryption-supported VMs, and shielded VMs, and create and deploy shielded VMs using signed template disks with BitLocker encryption and provisioning data files.

Learning objectives

After completing this module, you'll be able to:

  • Describe the features and functionality of the HGS in Windows Server.

  • Describe the attestation options available with the HGS.

  • Describe shielded VMs, their creation, and their deployment.

Prerequisites

To get the best learning experience from this module, you should have knowledge and experience of:

  • Windows Server.

  • Working with virtualization technologies.

  • Encryption technologies and concepts.