Azure DC2s_v3 SGX: DCAP verification returns 0xA007 / INTEL-SA-00615 with MMIO mitigation warning

jayapragash dakshnamurthy 0 Reputation points
2026-10-02T18:13:26.4633333+00:00

I am testing an Intel SGX enclave on an Azure VM and need clarification about the attestation result and platform mitigation requirements.

Environment:

  • VM size: Standard_DC2s_v3

Region: East US

OS: Ubuntu 24.04.4 LTS

Kernel: 6.17.0-1022-azure

CPU reported by guest: Intel Xeon Platinum 8370C

Intel SGX SDK/PSW: 2.30.101.1

Intel DCAP quote verification library: 1.27.101.1

An SGX quote generated on the Azure VM was independently checked using Intel’s native Quote Verification Library on a separate machine.

Verification output:

Verification API call succeeded.

Collateral expiration status: 0

Quote verification result: 0xA007 (SGX_QL_QV_RESULT_SW_HARDENING_NEEDED)

Advisory: INTEL-SA-00615

The enclave’s MRENCLAVE and MRSIGNER match the signed build, and the quote’s DEBUG attribute is disabled. A modified quote was rejected. Our authorization policy currently blocks token issuance pending clarification of the conditional verification result.

Inside the Azure guest, this command: cat /sys/devices/system/cpu/vulnerabilities/mmio_stale_data

returns: “Vulnerable: Clear CPU buffers attempted, no microcode; SMT Host state unknown”

I understand that guest-visible CPU capabilities may not fully reflect physical-host mitigations. I am therefore seeking clarification rather than assuming the Azure host is unpatched.

Questions:

What host microcode, hypervisor mitigations, and SMT isolation assurances apply to DCsv3 VMs for INTEL-SA-00615?

Can this guest warning appear when the physical host is adequately mitigated?

What enclave software hardening must a relying party verify before accepting this specific 0xA007 result?

Is any Azure-supported configuration change or platform remediation required?

Could an Azure Confidential Computing / Intel SGX specialist advise? I can provide sanitized verification logs and build details if needed.I am testing an Intel SGX enclave on an Azure VM and need clarification about the attestation result and platform mitigation requirements.

Environment:

VM size: Standard_DC2s_v3

Region: East US

OS: Ubuntu 24.04.4 LTS

Kernel: 6.17.0-1022-azure

CPU reported by guest: Intel Xeon Platinum 8370C

Intel SGX SDK/PSW: 2.30.101.1

Intel DCAP quote verification library: 1.27.101.1

An SGX quote generated on the Azure VM was independently checked using Intel’s native Quote Verification Library on a separate machine.

Verification output:

Verification API call succeeded.

Collateral expiration status: 0

Quote verification result: 0xA007 (SGX_QL_QV_RESULT_SW_HARDENING_NEEDED)

Advisory: INTEL-SA-00615

The enclave’s MRENCLAVE and MRSIGNER match the signed build, and the quote’s DEBUG attribute is disabled. A modified quote was rejected. Our authorization policy currently blocks token issuance pending clarification of the conditional verification result.

Inside the Azure guest, this command:
cat /sys/devices/system/cpu/vulnerabilities/mmio_stale_data

returns:
“Vulnerable: Clear CPU buffers attempted, no microcode; SMT Host state unknown”

I understand that guest-visible CPU capabilities may not fully reflect physical-host mitigations. I am therefore seeking clarification rather than assuming the Azure host is unpatched.

Questions:

What host microcode, hypervisor mitigations, and SMT isolation assurances apply to DCsv3 VMs for INTEL-SA-00615?

Can this guest warning appear when the physical host is adequately mitigated?

What enclave software hardening must a relying party verify before accepting this specific 0xA007 result?

Is any Azure-supported configuration change or platform remediation required?

Could an Azure Confidential Computing / Intel SGX specialist advise? I can provide sanitized verification logs and build details if needed.

Azure Virtual Machines
Azure Virtual Machines

An Azure service that is used to provision Windows and Linux virtual machines.

0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.