# Choose whether cluster anti-affinity should yield during a node outage

> Should two clustered roles stay separated even when only one node remains available?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-158-choose-whether-cluster-anti-affinity-should-yield-during-a-node-outage/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:33+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Should two clustered roles stay separated even when only one node remains available?

## Potentially affected

Administrators setting anti-affinity for Windows failover-cluster roles.

## DSE recommendation

Record that tradeoff before choosing the anti-affinity setting.

## Article

## Source facts

Microsoft uses anti-affinity to try to keep selected roles on different nodes. The AntiAffinityClassNames setting is a soft constraint; the documentation also describes enforcing a hard separation. Microsoft warns that, in a two-node configuration with enforced anti-affinity, losing one node means both separated groups cannot run. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/failover-clustering/Cluster-Affinity).

## Applicability

Identify the roles, their resource demand, available nodes, and service priorities. Ask workload owners whether maintaining separation or keeping both services running should take precedence during reduced capacity.

## DSE recommendation

Record that tradeoff before choosing the anti-affinity setting. Name the roles that belong to the same separation class and define the accepted outage behavior. Have the cluster owner review capacity and the application owners approve any intentional loss of service under enforcement.

## Verification

Inspect the configured class values and observe placement under normal conditions. In an approved maintenance test, remove one eligible node and compare the resulting role state with the decision. Preserve an unavailable role as an expected or unexpected outcome explicitly; do not equate policy enforcement with application availability.

## Official references

[Microsoft Learn: Cluster affinity](https://learn.microsoft.com/en-us/windows-server/failover-clustering/Cluster-Affinity). Source reviewed September 8, 2026.

## Primary reference

- Name: Cluster affinity
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/failover-clustering/Cluster-Affinity
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose whether cluster anti-affinity should yield during a node outage,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-158-choose-whether-cluster-anti-affinity-should-yield-during-a-node-outage/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
