# Review the live-migration authentication path after a Windows Server upgrade

> Which authentication configuration should be reviewed for nonclustered Hyper-V live migration?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-161-review-the-live-migration-authentication-path-after-a-windows-server-upgrade/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:14:30+00:00
- Modified: 2026-09-08T18:26:31+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which authentication configuration should be reviewed for nonclustered Hyper-V live migration?

## Potentially affected

Administrators configuring live migration between nonclustered Hyper-V hosts.

## DSE recommendation

Have the virtualization and directory owners review the required services and destination hosts before configuring delegation.

## Article

## Source facts

Microsoft’s nonclustered live-migration procedure requires choosing how the source and destination authenticate migration traffic; the choice affects whether the operator must sign in to the source first. The source states that the Windows Server 2025 Credential Guard default on domain-member servers prevents the prior CredSSP-based migration approach and directs administrators toward Kerberos constrained delegation. Its Kerberos setup procedure uses an account with Domain Administrators membership. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/deploy/Set-up-hosts-for-live-migration-without-Failover-Clustering).

## Applicability

Check both host releases, domain roles, authentication settings, management location, and whether storage will move. Review the source’s exact delegation requirements for the selected migration path.

## DSE recommendation

Have the virtualization and directory owners review the required services and destination hosts before configuring delegation. Document the intended operator entry point and the authorization used for the setup. Keep the change limited to the approved migration relationship and preserve the previous host configuration.

## Verification

Initiate a controlled migration from the intended management location and inspect the source and destination results. Include the required storage-movement case if applicable. Record authentication failures separately from network or storage failures, and reconcile them before relying on the upgraded hosts for planned moves.

## Official references

[Microsoft Learn: Set up hosts for live migration without Failover Clustering](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/deploy/Set-up-hosts-for-live-migration-without-Failover-Clustering). Source reviewed September 8, 2026.

## Primary reference

- Name: Set up hosts for live migration without Failover Clustering
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/deploy/Set-up-hosts-for-live-migration-without-Failover-Clustering
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review the live-migration authentication path after a Windows Server upgrade,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-161-review-the-live-migration-authentication-path-after-a-windows-server-upgrade/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
