Against which threat does Managed Device Attestation help provide protection?
Managed Device Attestation validates hardware-backed evidence of a device’s security and boot properties, so a compromised device cannot reliably falsify those properties to management systems. Microsoft documents that TPM-protected attestation data can be trusted even when a device is compromised and that critical properties cannot be spoofed, including in the presence of kernel-level malware or a rootkit.
Community Discussion