{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/",
        "slug": "dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/"
        },
        "title": "Separate Windows Admin Center gateway users from gateway administrators",
        "summary": "Who should be able to use a WAC gateway and who should change its access policy?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:32+00:00",
        "modified_at": "2026-09-08T18:29:33+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 226,
        "potentially_affected": "Administrators assigning Windows Admin Center gateway access permissions.",
        "dse_recommendation": "Create a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration.",
        "primary_source": {
            "name": "Configuring user access control and permissions",
            "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft says gateway users can use the WAC gateway to manage servers but cannot change its access permissions or authentication mechanism. The documented default access model uses Active Directory or local machine groups. When Entra authentication is selected, the page directs administrators to manage WAC user and administrator access permissions through the Azure portal. <a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the deployed gateway access model and the groups currently assigned to its roles. Separate permission to use the gateway from authority to change the gateway&#8217;s own access policy. Review the managed servers&#8217; permissions independently before interpreting a gateway role as complete task authorization.</p>\n<h2>DSE recommendation</h2>\n<p>Create a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration. Have a second administrator review broad or inherited group memberships. Preserve the current assignments and pilot a representative operator account. Include the procedure for removing an operator who changes duties and for recovering access if the role configuration is mistaken.</p>\n<h2>Verification</h2>\n<p>Verify that an approved gateway user can enter the gateway but cannot alter access settings. Test an excluded identity and confirm that the authorized administrator can review the assignments. Record the interface used to manage permissions and the resulting membership. Keep server-task authorization results as separate evidence.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configuring user access control and permissions</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft says gateway users can use the WAC gateway to manage servers but cannot change its access permissions or authentication mechanism. The documented default access model uses Active Directory or local machine groups. When Entra authentication is selected, the page directs administrators to manage WAC user and administrator access permissions through the Azure portal. Microsoft Learn.\nApplicability\nIdentify the deployed gateway access model and the groups currently assigned to its roles. Separate permission to use the gateway from authority to change the gateway’s own access policy. Review the managed servers’ permissions independently before interpreting a gateway role as complete task authorization.\nDSE recommendation\nCreate a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration. Have a second administrator review broad or inherited group memberships. Preserve the current assignments and pilot a representative operator account. Include the procedure for removing an operator who changes duties and for recovering access if the role configuration is mistaken.\nVerification\nVerify that an approved gateway user can enter the gateway but cannot alter access settings. Test an excluded identity and confirm that the authorized administrator can review the assignments. Record the interface used to manage permissions and the resulting membership. Keep server-task authorization results as separate evidence.\nOfficial references\nMicrosoft Learn: Configuring user access control and permissions. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft says gateway users can use the WAC gateway to manage servers but cannot change its access permissions or authentication mechanism. The documented default access model uses Active Directory or local machine groups. When Entra authentication is selected, the page directs administrators to manage WAC user and administrator access permissions through the Azure portal. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control).\n\n## Applicability\n\nIdentify the deployed gateway access model and the groups currently assigned to its roles. Separate permission to use the gateway from authority to change the gateway’s own access policy. Review the managed servers’ permissions independently before interpreting a gateway role as complete task authorization.\n\n## DSE recommendation\n\nCreate a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration. Have a second administrator review broad or inherited group memberships. Preserve the current assignments and pilot a representative operator account. Include the procedure for removing an operator who changes duties and for recovering access if the role configuration is mistaken.\n\n## Verification\n\nVerify that an approved gateway user can enter the gateway but cannot alter access settings. Test an excluded identity and confirm that the authorized administrator can review the assignments. Record the interface used to manage permissions and the resulting membership. Keep server-task authorization results as separate evidence.\n\n## Official references\n\n[Microsoft Learn: Configuring user access control and permissions](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate Windows Admin Center gateway users from gateway administrators",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/",
                "headline": "Separate Windows Admin Center gateway users from gateway administrators",
                "description": "Who should be able to use a WAC gateway and who should change its access policy?",
                "abstract": "Who should be able to use a WAC gateway and who should change its access policy?",
                "articleBody": "Source facts\nMicrosoft says gateway users can use the WAC gateway to manage servers but cannot change its access permissions or authentication mechanism. The documented default access model uses Active Directory or local machine groups. When Entra authentication is selected, the page directs administrators to manage WAC user and administrator access permissions through the Azure portal. Microsoft Learn.\nApplicability\nIdentify the deployed gateway access model and the groups currently assigned to its roles. Separate permission to use the gateway from authority to change the gateway’s own access policy. Review the managed servers’ permissions independently before interpreting a gateway role as complete task authorization.\nDSE recommendation\nCreate a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration. Have a second administrator review broad or inherited group memberships. Preserve the current assignments and pilot a representative operator account. Include the procedure for removing an operator who changes duties and for recovering access if the role configuration is mistaken.\nVerification\nVerify that an approved gateway user can enter the gateway but cannot alter access settings. Test an excluded identity and confirm that the authorized administrator can review the assignments. Record the interface used to manage permissions and the resulting membership. Keep server-task authorization results as separate evidence.\nOfficial references\nMicrosoft Learn: Configuring user access control and permissions. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:32+00:00",
                "dateModified": "2026-09-08T18:29:33+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate Windows Admin Center gateway users from gateway administrators"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 226,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configuring user access control and permissions",
                    "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control"
                }
            }
        ]
    }
}