{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/",
        "slug": "dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/"
        },
        "title": "Prepare an additional HGS node without overlooking its identity and DNS prerequisites",
        "summary": "What must be checked before adding another Host Guardian Service node?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:16:58+00:00",
        "modified_at": "2026-09-08T18:17:13+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 223,
        "potentially_affected": "Use this review when adding capacity or resilience to an existing HGS deployment.",
        "dse_recommendation": "Compare the proposed node with the primary before initialization.",
        "primary_source": {
            "name": "Configure additional HGS nodes",
            "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft recommends a highly available HGS cluster for production so a failed HGS node does not prevent shielded virtual machines from starting. Secondary nodes are optional in test environments. An additional node should match the primary node&#8217;s hardware and software, share the HGS network, and resolve the other HGS servers by name. The documented procedure joins it to the same domain as the first HGS node. <a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review when adding capacity or resilience to an existing HGS deployment. Identify its forest model and certificate arrangement, then follow the matching branch of the source procedure for that environment.</p>\n<h2>DSE recommendation</h2>\n<p>Compare the proposed node with the primary before initialization. Assign owners for name resolution, domain membership, certificates, and the workload acceptance test. Record the existing HGS service state and plan the addition during an agreed maintenance period. Keep the new node out of the accepted service inventory until its configuration and intended role have been reviewed.</p>\n<h2>Verification</h2>\n<p>Check name resolution and domain membership from the added node. Verify the completed HGS configuration against the selected procedure and perform an approved shielded-VM start test. Include a controlled loss of the node intended to be redundant. Record which nodes participated and investigate any failed start separately from successful installation.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure additional HGS nodes</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft recommends a highly available HGS cluster for production so a failed HGS node does not prevent shielded virtual machines from starting. Secondary nodes are optional in test environments. An additional node should match the primary node’s hardware and software, share the HGS network, and resolve the other HGS servers by name. The documented procedure joins it to the same domain as the first HGS node. Microsoft documentation.\nApplicability\nUse this review when adding capacity or resilience to an existing HGS deployment. Identify its forest model and certificate arrangement, then follow the matching branch of the source procedure for that environment.\nDSE recommendation\nCompare the proposed node with the primary before initialization. Assign owners for name resolution, domain membership, certificates, and the workload acceptance test. Record the existing HGS service state and plan the addition during an agreed maintenance period. Keep the new node out of the accepted service inventory until its configuration and intended role have been reviewed.\nVerification\nCheck name resolution and domain membership from the added node. Verify the completed HGS configuration against the selected procedure and perform an approved shielded-VM start test. Include a controlled loss of the node intended to be redundant. Record which nodes participated and investigate any failed start separately from successful installation.\nOfficial references\nMicrosoft Learn: Configure additional HGS nodes. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft recommends a highly available HGS cluster for production so a failed HGS node does not prevent shielded virtual machines from starting. Secondary nodes are optional in test environments. An additional node should match the primary node’s hardware and software, share the HGS network, and resolve the other HGS servers by name. The documented procedure joins it to the same domain as the first HGS node. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes).\n\n## Applicability\n\nUse this review when adding capacity or resilience to an existing HGS deployment. Identify its forest model and certificate arrangement, then follow the matching branch of the source procedure for that environment.\n\n## DSE recommendation\n\nCompare the proposed node with the primary before initialization. Assign owners for name resolution, domain membership, certificates, and the workload acceptance test. Record the existing HGS service state and plan the addition during an agreed maintenance period. Keep the new node out of the accepted service inventory until its configuration and intended role have been reviewed.\n\n## Verification\n\nCheck name resolution and domain membership from the added node. Verify the completed HGS configuration against the selected procedure and perform an approved shielded-VM start test. Include a controlled loss of the node intended to be redundant. Record which nodes participated and investigate any failed start separately from successful installation.\n\n## Official references\n\n[Microsoft Learn: Configure additional HGS nodes](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Prepare an additional HGS node without overlooking its identity and DNS prerequisites",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/",
                "headline": "Prepare an additional HGS node without overlooking its identity and DNS prerequisites",
                "description": "What must be checked before adding another Host Guardian Service node?",
                "abstract": "What must be checked before adding another Host Guardian Service node?",
                "articleBody": "Source facts\nMicrosoft recommends a highly available HGS cluster for production so a failed HGS node does not prevent shielded virtual machines from starting. Secondary nodes are optional in test environments. An additional node should match the primary node’s hardware and software, share the HGS network, and resolve the other HGS servers by name. The documented procedure joins it to the same domain as the first HGS node. Microsoft documentation.\nApplicability\nUse this review when adding capacity or resilience to an existing HGS deployment. Identify its forest model and certificate arrangement, then follow the matching branch of the source procedure for that environment.\nDSE recommendation\nCompare the proposed node with the primary before initialization. Assign owners for name resolution, domain membership, certificates, and the workload acceptance test. Record the existing HGS service state and plan the addition during an agreed maintenance period. Keep the new node out of the accepted service inventory until its configuration and intended role have been reviewed.\nVerification\nCheck name resolution and domain membership from the added node. Verify the completed HGS configuration against the selected procedure and perform an approved shielded-VM start test. Include a controlled loss of the node intended to be redundant. Record which nodes participated and investigate any failed start separately from successful installation.\nOfficial references\nMicrosoft Learn: Configure additional HGS nodes. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:16:58+00:00",
                "dateModified": "2026-09-08T18:17:13+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Prepare an additional HGS node without overlooking its identity and DNS prerequisites"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 223,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure additional HGS nodes",
                    "url": "https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes"
                }
            }
        ]
    }
}