{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/",
        "slug": "dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/"
        },
        "title": "Separate Windows Admin Center gateway sign-in from server access",
        "summary": "Which authentication layer is being tested when an administrator opens Windows Admin Center?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:16+00:00",
        "modified_at": "2026-09-08T18:29:34+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 220,
        "potentially_affected": "Teams reviewing identity-provider and authentication options for a Windows Admin Center gateway.",
        "dse_recommendation": "Draw the two access stages and assign an owner to each.",
        "primary_source": {
            "name": "User access options with Windows Admin Center",
            "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Windows Admin Center gateway administrators can select Active Directory or local groups, or Microsoft Entra ID, as the identity provider. Requiring Microsoft Entra authentication for the gateway enables use of its Conditional Access and multifactor authentication capabilities. Access to the gateway does not itself grant access to managed servers. <a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify whether the current question concerns gateway sign-in or authorization on a particular managed server. Inventory the chosen identity provider and any applicable access policy. Do not treat a successful gateway challenge as evidence that server permissions are correct.</p>\n<h2>DSE recommendation</h2>\n<p>Draw the two access stages and assign an owner to each. For an Entra-backed gateway, have the identity owner define the intended Conditional Access test conditions and recovery access. Have the server owner independently approve the target permissions. Use a pilot administrator account with known memberships so an unexpected result can be traced to the correct layer without widening either permission set.</p>\n<h2>Verification</h2>\n<p>Test gateway sign-in under an allowed condition and an intentionally denied condition. For the allowed gateway session, attempt access to both an approved server and a server outside the pilot permission set. Record the policy and authorization outcome separately, including the stage at which a denied attempt stopped.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: User access options with Windows Admin Center</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nWindows Admin Center gateway administrators can select Active Directory or local groups, or Microsoft Entra ID, as the identity provider. Requiring Microsoft Entra authentication for the gateway enables use of its Conditional Access and multifactor authentication capabilities. Access to the gateway does not itself grant access to managed servers. Microsoft Learn.\nApplicability\nIdentify whether the current question concerns gateway sign-in or authorization on a particular managed server. Inventory the chosen identity provider and any applicable access policy. Do not treat a successful gateway challenge as evidence that server permissions are correct.\nDSE recommendation\nDraw the two access stages and assign an owner to each. For an Entra-backed gateway, have the identity owner define the intended Conditional Access test conditions and recovery access. Have the server owner independently approve the target permissions. Use a pilot administrator account with known memberships so an unexpected result can be traced to the correct layer without widening either permission set.\nVerification\nTest gateway sign-in under an allowed condition and an intentionally denied condition. For the allowed gateway session, attempt access to both an approved server and a server outside the pilot permission set. Record the policy and authorization outcome separately, including the stage at which a denied attempt stopped.\nOfficial references\nMicrosoft Learn: User access options with Windows Admin Center. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nWindows Admin Center gateway administrators can select Active Directory or local groups, or Microsoft Entra ID, as the identity provider. Requiring Microsoft Entra authentication for the gateway enables use of its Conditional Access and multifactor authentication capabilities. Access to the gateway does not itself grant access to managed servers. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options).\n\n## Applicability\n\nIdentify whether the current question concerns gateway sign-in or authorization on a particular managed server. Inventory the chosen identity provider and any applicable access policy. Do not treat a successful gateway challenge as evidence that server permissions are correct.\n\n## DSE recommendation\n\nDraw the two access stages and assign an owner to each. For an Entra-backed gateway, have the identity owner define the intended Conditional Access test conditions and recovery access. Have the server owner independently approve the target permissions. Use a pilot administrator account with known memberships so an unexpected result can be traced to the correct layer without widening either permission set.\n\n## Verification\n\nTest gateway sign-in under an allowed condition and an intentionally denied condition. For the allowed gateway session, attempt access to both an approved server and a server outside the pilot permission set. Record the policy and authorization outcome separately, including the stage at which a denied attempt stopped.\n\n## Official references\n\n[Microsoft Learn: User access options with Windows Admin Center](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate Windows Admin Center gateway sign-in from server access",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/",
                "headline": "Separate Windows Admin Center gateway sign-in from server access",
                "description": "Which authentication layer is being tested when an administrator opens Windows Admin Center?",
                "abstract": "Which authentication layer is being tested when an administrator opens Windows Admin Center?",
                "articleBody": "Source facts\nWindows Admin Center gateway administrators can select Active Directory or local groups, or Microsoft Entra ID, as the identity provider. Requiring Microsoft Entra authentication for the gateway enables use of its Conditional Access and multifactor authentication capabilities. Access to the gateway does not itself grant access to managed servers. Microsoft Learn.\nApplicability\nIdentify whether the current question concerns gateway sign-in or authorization on a particular managed server. Inventory the chosen identity provider and any applicable access policy. Do not treat a successful gateway challenge as evidence that server permissions are correct.\nDSE recommendation\nDraw the two access stages and assign an owner to each. For an Entra-backed gateway, have the identity owner define the intended Conditional Access test conditions and recovery access. Have the server owner independently approve the target permissions. Use a pilot administrator account with known memberships so an unexpected result can be traced to the correct layer without widening either permission set.\nVerification\nTest gateway sign-in under an allowed condition and an intentionally denied condition. For the allowed gateway session, attempt access to both an approved server and a server outside the pilot permission set. Record the policy and authorization outcome separately, including the stage at which a denied attempt stopped.\nOfficial references\nMicrosoft Learn: User access options with Windows Admin Center. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:16+00:00",
                "dateModified": "2026-09-08T18:29:34+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-235-separate-windows-admin-center-gateway-sign-in-from-server-access/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate Windows Admin Center gateway sign-in from server access"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 220,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "User access options with Windows Admin Center",
                    "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options"
                }
            }
        ]
    }
}