Skip to content

Latest commit

 

History

History
46 lines (36 loc) · 4.7 KB

guarded-fabric-deploying-hgs-overview.md

File metadata and controls

46 lines (36 loc) · 4.7 KB
title description ms.topic ms.assetid manager author ms.author ms.date
Deploying the Host Guardian Service
Learn more about: Deploying the Host Guardian Service
article
310b63d9-5ac7-4961-98ef-103af45d706a
dongill
robinharwood
wscontent
01/14/2020

Deploying the Host Guardian Service

Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016

One of the most important goals of providing a hosted environment is to guarantee the security of the virtual machines running in the environment. As a cloud service provider or enterprise private cloud administrator, you can use a guarded fabric to provide a more secure environment for VMs. A guarded fabric consists of one Host Guardian Service (HGS) - typically, a cluster of three nodes - plus one or more guarded hosts, and a set of shielded virtual machines (VMs).

Video: Deploying a guarded fabric

[!VIDEO https://www.microsoft.com/videoplayer/embed/dcd8e99f-36f1-4bc8-b3d2-9576da38d9f1?autoplay=false]

Deployment tasks for guarded fabrics and shielded VMs

The following table breaks down the tasks to deploy a guarded fabric and create shielded VMs according to different administrator roles. Note that when the HGS admin configures HGS with authorized Hyper-V hosts, a fabric admin will collect and provide identifying information about the hosts at the same time.

| Step and link to content | Image | |--|--|--| | 1 - Verify HGS prerequisites | Step 1, verify prerequisites | | 2 - Configure first HGS node | Step 2, configure the first HGS node | | 3 - Configure additional HGS nodes | Step 3, configure additional HGS nodes | | 4 - Configure fabric DNS | Step 4, configure fabric DNS | | 5 - Verify host prerequisites (Key) and Verify host prerequisites (TPM) | Step 5, verify host prerequisite key and host prerequisite TPM | | 6 - Create host key (Key) andCollect host information (TPM) | Step 6, create host key and collect host info | | 7 - Configure HGS with host information | Step 7, add host info to HGS | | 8 - Confirm hosts can attest | Step 8, confirm host can attest | | 9 - Configure VMM (optional) | Step 9, configure VMM (optional) | | 10 - Create template disks | Step 10, create template disks | | 11 - Create a VM shielding helper disk for VMM (optional) | Step 11, create a VM shielding help disk for VMM | | 12 - Set up Windows Azure Pack (optional) | Step 12, set up Windows Azure Pack (optional) | | 13 - Create shielding data file | Step 13, create a shielding data file | | 14 - Create shielded VMs using Windows Azure Pack | Step 14, create shielded VMs using Windows Azure Pack | | 15 - Create shielded VMs using VMM | Step 15, create shielded VMs using VMM |

Additional References