# Prepare an additional HGS node without overlooking its identity and DNS prerequisites

> What must be checked before adding another Host Guardian Service node?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:16:58+00:00
- Modified: 2026-09-08T18:17:13+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What must be checked before adding another Host Guardian Service node?

## Potentially affected

Use this review when adding capacity or resilience to an existing HGS deployment.

## DSE recommendation

Compare the proposed node with the primary before initialization.

## Article

## Source facts

Microsoft recommends a highly available HGS cluster for production so a failed HGS node does not prevent shielded virtual machines from starting. Secondary nodes are optional in test environments. An additional node should match the primary node’s hardware and software, share the HGS network, and resolve the other HGS servers by name. The documented procedure joins it to the same domain as the first HGS node. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes).

## Applicability

Use this review when adding capacity or resilience to an existing HGS deployment. Identify its forest model and certificate arrangement, then follow the matching branch of the source procedure for that environment.

## DSE recommendation

Compare the proposed node with the primary before initialization. Assign owners for name resolution, domain membership, certificates, and the workload acceptance test. Record the existing HGS service state and plan the addition during an agreed maintenance period. Keep the new node out of the accepted service inventory until its configuration and intended role have been reviewed.

## Verification

Check name resolution and domain membership from the added node. Verify the completed HGS configuration against the selected procedure and perform an approved shielded-VM start test. Include a controlled loss of the node intended to be redundant. Record which nodes participated and investigate any failed start separately from successful installation.

## Official references

[Microsoft Learn: Configure additional HGS nodes](https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes). Source reviewed September 8, 2026.

## Primary reference

- Name: Configure additional HGS nodes
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/security/guarded-fabric-shielded-vm/guarded-fabric-configure-additional-hgs-nodes
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Prepare an additional HGS node without overlooking its identity and DNS prerequisites,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-013-prepare-an-additional-hgs-node-without-overlooking-its-identity-and-dns/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
