# Qualify the account model for live migration in a workgroup cluster

> What authentication prerequisites distinguish workgroup-cluster live migration?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-227-qualify-the-account-model-for-live-migration-in-a-workgroup-cluster/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:24+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What authentication prerequisites distinguish workgroup-cluster live migration?

## Potentially affected

Administrators planning live migration within Windows Server 2025 workgroup clusters.

## DSE recommendation

Have the virtualization and identity owners document how the required node accounts will be provisioned, protected, rotated, and removed.

## Article

## Source facts

Microsoft distinguishes workgroup clustering, introduced earlier, from workgroup-cluster live migration support introduced with Windows Server 2025. The documented setup requires a running cluster of at least two nodes and matching local account names and passwords on the nodes. The cluster uses self-signed PKU2U certificates for movement between hosts rather than Kerberos in this workflow. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/manage/live-migration-workgroup-cluster).

## Applicability

Confirm that the proposed hosts and cluster match the current support requirements. Identify the local-account lifecycle and the operators responsible for each node. Do not transfer assumptions from a domain-based constrained-delegation design into the workgroup procedure.

## DSE recommendation

Have the virtualization and identity owners document how the required node accounts will be provisioned, protected, rotated, and removed. Keep credentials out of runbooks and ordinary evidence files. Select a representative VM and confirm its source and destination configuration before a pilot. Include a recovery management path if account consistency or the migration relationship fails.

## Verification

Perform the approved live move and verify the VM’s resulting host and application behavior. Record the documented authentication configuration and any failed connection separately from storage or hardware compatibility issues. Check the operational procedure after an approved account-lifecycle exercise. Accept the workflow only when its local-account ownership is maintainable across every intended node.

## Official references

[Microsoft Learn: Use live migration with workgroup clusters in Windows Server](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/manage/live-migration-workgroup-cluster). Source reviewed September 8, 2026.

## Primary reference

- Name: Use live migration with workgroup clusters in Windows Server
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/manage/live-migration-workgroup-cluster
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Qualify the account model for live migration in a workgroup cluster,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-227-qualify-the-account-model-for-live-migration-in-a-workgroup-cluster/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
