Securing Hyper-V workloads with Guarded Fabric
We will introduce this section by looking at the Guarded Fabric security solution at an overview level and then explore each component in the following subsections.
Guarded Fabric
Guarded Fabric is a collection of component services and capabilities that allows a security solution to protect VMs against inspection, theft, and tampering, and malicious actors, humans, or malware from compromised VMs or hosts.
Guarded Fabric is comprised of the following components at its core:
- Shielded VM: You specify templates and images that a VM must use to be a Shielded VM.
- Guarded Host: You specify which hosts are secure for running Shielded VMs.
- Host Guardian Service (HGS): This ensures that only authorized and secure Guarded Fabric Hosts can run Shielded VMs. It provides the key service to the Guarded Hosts.
The Guarded Fabric security solution is shown in the following diagram:
Figure 9.13 –...