{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/",
        "slug": "dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/"
        },
        "title": "Retain a DNS plan when building a workgroup failover cluster",
        "summary": "What infrastructure and node-identity assumptions remain in a workgroup cluster?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:15:20+00:00",
        "modified_at": "2026-09-08T18:23:26+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 205,
        "potentially_affected": "Administrators evaluating Windows Server workgroup failover clusters.",
        "dse_recommendation": "Document the node names, DNS suffix, name-resolution ownership, account management, and prior domain membership.",
        "primary_source": {
            "name": "Create a workgroup cluster in Windows Server",
            "url": "https://learn.microsoft.com/en-us/windows-server/failover-clustering/create-workgroup-cluster",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Workgroup clusters use nodes outside an Active Directory domain or forest, but Microsoft still requires DNS. The prerequisites require every node to run the same Windows Server version and remain in a workgroup. Previously domain-joined nodes must also be renamed after leaving the domain to remove cached AD information. The initial configuration includes an identical account on the nodes, trusted-host configuration, and a common primary DNS suffix. <a href=\"https://learn.microsoft.com/en-us/windows-server/failover-clustering/create-workgroup-cluster\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft documentation</a>.</p>\n<h2>Applicability</h2>\n<p>Check the intended workload and server release against the supported workload table. Review storage, quorum, credentials, and name resolution as separate prerequisites before deciding that a workgroup design fits the application.</p>\n<h2>DSE recommendation</h2>\n<p>Document the node names, DNS suffix, name-resolution ownership, account management, and prior domain membership. Ask the platform owner to review how administrative access will be maintained. Preserve the original node identity and explicitly plan any required rename before starting cluster creation.</p>\n<h2>Verification</h2>\n<p>Verify consistent node configuration and resolution of the intended names from every member. Run the documented validation and test the approved workload and maintenance path. Keep workload-support evidence alongside the results, and resolve a node-identity or DNS discrepancy before admitting the node to service.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/failover-clustering/create-workgroup-cluster\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create a workgroup cluster in Windows Server</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nWorkgroup clusters use nodes outside an Active Directory domain or forest, but Microsoft still requires DNS. The prerequisites require every node to run the same Windows Server version and remain in a workgroup. Previously domain-joined nodes must also be renamed after leaving the domain to remove cached AD information. The initial configuration includes an identical account on the nodes, trusted-host configuration, and a common primary DNS suffix. Microsoft documentation.\nApplicability\nCheck the intended workload and server release against the supported workload table. Review storage, quorum, credentials, and name resolution as separate prerequisites before deciding that a workgroup design fits the application.\nDSE recommendation\nDocument the node names, DNS suffix, name-resolution ownership, account management, and prior domain membership. Ask the platform owner to review how administrative access will be maintained. Preserve the original node identity and explicitly plan any required rename before starting cluster creation.\nVerification\nVerify consistent node configuration and resolution of the intended names from every member. Run the documented validation and test the approved workload and maintenance path. Keep workload-support evidence alongside the results, and resolve a node-identity or DNS discrepancy before admitting the node to service.\nOfficial references\nMicrosoft Learn: Create a workgroup cluster in Windows Server. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nWorkgroup clusters use nodes outside an Active Directory domain or forest, but Microsoft still requires DNS. The prerequisites require every node to run the same Windows Server version and remain in a workgroup. Previously domain-joined nodes must also be renamed after leaving the domain to remove cached AD information. The initial configuration includes an identical account on the nodes, trusted-host configuration, and a common primary DNS suffix. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/failover-clustering/create-workgroup-cluster).\n\n## Applicability\n\nCheck the intended workload and server release against the supported workload table. Review storage, quorum, credentials, and name resolution as separate prerequisites before deciding that a workgroup design fits the application.\n\n## DSE recommendation\n\nDocument the node names, DNS suffix, name-resolution ownership, account management, and prior domain membership. Ask the platform owner to review how administrative access will be maintained. Preserve the original node identity and explicitly plan any required rename before starting cluster creation.\n\n## Verification\n\nVerify consistent node configuration and resolution of the intended names from every member. Run the documented validation and test the approved workload and maintenance path. Keep workload-support evidence alongside the results, and resolve a node-identity or DNS discrepancy before admitting the node to service.\n\n## Official references\n\n[Microsoft Learn: Create a workgroup cluster in Windows Server](https://learn.microsoft.com/en-us/windows-server/failover-clustering/create-workgroup-cluster). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Retain a DNS plan when building a workgroup failover cluster",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/",
                "headline": "Retain a DNS plan when building a workgroup failover cluster",
                "description": "What infrastructure and node-identity assumptions remain in a workgroup cluster?",
                "abstract": "What infrastructure and node-identity assumptions remain in a workgroup cluster?",
                "articleBody": "Source facts\nWorkgroup clusters use nodes outside an Active Directory domain or forest, but Microsoft still requires DNS. The prerequisites require every node to run the same Windows Server version and remain in a workgroup. Previously domain-joined nodes must also be renamed after leaving the domain to remove cached AD information. The initial configuration includes an identical account on the nodes, trusted-host configuration, and a common primary DNS suffix. Microsoft documentation.\nApplicability\nCheck the intended workload and server release against the supported workload table. Review storage, quorum, credentials, and name resolution as separate prerequisites before deciding that a workgroup design fits the application.\nDSE recommendation\nDocument the node names, DNS suffix, name-resolution ownership, account management, and prior domain membership. Ask the platform owner to review how administrative access will be maintained. Preserve the original node identity and explicitly plan any required rename before starting cluster creation.\nVerification\nVerify consistent node configuration and resolution of the intended names from every member. Run the documented validation and test the approved workload and maintenance path. Keep workload-support evidence alongside the results, and resolve a node-identity or DNS discrepancy before admitting the node to service.\nOfficial references\nMicrosoft Learn: Create a workgroup cluster in Windows Server. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:15:20+00:00",
                "dateModified": "2026-09-08T18:23:26+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-111-retain-a-dns-plan-when-building-a-workgroup-failover-cluster/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Retain a DNS plan when building a workgroup failover cluster"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 205,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create a workgroup cluster in Windows Server",
                    "url": "https://learn.microsoft.com/en-us/windows-server/failover-clustering/create-workgroup-cluster"
                }
            }
        ]
    }
}