{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/",
        "slug": "dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/"
        },
        "title": "Plan the WAC high-availability transition across the 2410 architecture change",
        "summary": "What deployment constraints apply when upgrading an older highly available WAC gateway?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:13+00:00",
        "modified_at": "2026-09-08T18:29:34+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 1,
        "word_count": 218,
        "potentially_affected": "Administrators upgrading Windows Admin Center gateways hosted in failover clusters.",
        "dse_recommendation": "Have the gateway owner prepare the documented uninstall-and-reinstall transition in a representative cluster.",
        "primary_source": {
            "name": "Deploy Windows Admin Center with High Availability",
            "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft describes the clustered WAC gateway as active-passive, with one active instance at a time. Its current guidance says highly available versions 2311 and earlier cannot directly upgrade to versions 2410 and later because of architectural changes. The documented high-availability prerequisites include shared persistent storage and the required certificate with its private key on every node. <a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the actual gateway version and deployment method before selecting an upgrade path. Review the current HA scripts and certificate requirements rather than using an ordinary single-server update procedure. Treat this transition as a deployment change with its own maintenance and recovery plan.</p>\n<h2>DSE recommendation</h2>\n<p>Have the gateway owner prepare the documented uninstall-and-reinstall transition in a representative cluster. Preserve the current configuration and required recovery material through approved handling. Assign ownership for the shared storage and certificate installation on each node. Maintain an alternative management route during the change and agree on the conditions that require stopping the rollout.</p>\n<h2>Verification</h2>\n<p>Verify the resulting gateway version, active instance, certificate presentation, and access to an intended managed server. Exercise the agreed node failover and confirm management resumes through the expected gateway name. Record any configuration that required restoration or recreation before accepting the upgraded highly available deployment.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Deploy Windows Admin Center with High Availability</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft describes the clustered WAC gateway as active-passive, with one active instance at a time. Its current guidance says highly available versions 2311 and earlier cannot directly upgrade to versions 2410 and later because of architectural changes. The documented high-availability prerequisites include shared persistent storage and the required certificate with its private key on every node. Microsoft Learn.\nApplicability\nIdentify the actual gateway version and deployment method before selecting an upgrade path. Review the current HA scripts and certificate requirements rather than using an ordinary single-server update procedure. Treat this transition as a deployment change with its own maintenance and recovery plan.\nDSE recommendation\nHave the gateway owner prepare the documented uninstall-and-reinstall transition in a representative cluster. Preserve the current configuration and required recovery material through approved handling. Assign ownership for the shared storage and certificate installation on each node. Maintain an alternative management route during the change and agree on the conditions that require stopping the rollout.\nVerification\nVerify the resulting gateway version, active instance, certificate presentation, and access to an intended managed server. Exercise the agreed node failover and confirm management resumes through the expected gateway name. Record any configuration that required restoration or recreation before accepting the upgraded highly available deployment.\nOfficial references\nMicrosoft Learn: Deploy Windows Admin Center with High Availability. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft describes the clustered WAC gateway as active-passive, with one active instance at a time. Its current guidance says highly available versions 2311 and earlier cannot directly upgrade to versions 2410 and later because of architectural changes. The documented high-availability prerequisites include shared persistent storage and the required certificate with its private key on every node. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability).\n\n## Applicability\n\nIdentify the actual gateway version and deployment method before selecting an upgrade path. Review the current HA scripts and certificate requirements rather than using an ordinary single-server update procedure. Treat this transition as a deployment change with its own maintenance and recovery plan.\n\n## DSE recommendation\n\nHave the gateway owner prepare the documented uninstall-and-reinstall transition in a representative cluster. Preserve the current configuration and required recovery material through approved handling. Assign ownership for the shared storage and certificate installation on each node. Maintain an alternative management route during the change and agree on the conditions that require stopping the rollout.\n\n## Verification\n\nVerify the resulting gateway version, active instance, certificate presentation, and access to an intended managed server. Exercise the agreed node failover and confirm management resumes through the expected gateway name. Record any configuration that required restoration or recreation before accepting the upgraded highly available deployment.\n\n## Official references\n\n[Microsoft Learn: Deploy Windows Admin Center with High Availability](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Plan the WAC high-availability transition across the 2410 architecture change",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/",
                "headline": "Plan the WAC high-availability transition across the 2410 architecture change",
                "description": "What deployment constraints apply when upgrading an older highly available WAC gateway?",
                "abstract": "What deployment constraints apply when upgrading an older highly available WAC gateway?",
                "articleBody": "Source facts\nMicrosoft describes the clustered WAC gateway as active-passive, with one active instance at a time. Its current guidance says highly available versions 2311 and earlier cannot directly upgrade to versions 2410 and later because of architectural changes. The documented high-availability prerequisites include shared persistent storage and the required certificate with its private key on every node. Microsoft Learn.\nApplicability\nIdentify the actual gateway version and deployment method before selecting an upgrade path. Review the current HA scripts and certificate requirements rather than using an ordinary single-server update procedure. Treat this transition as a deployment change with its own maintenance and recovery plan.\nDSE recommendation\nHave the gateway owner prepare the documented uninstall-and-reinstall transition in a representative cluster. Preserve the current configuration and required recovery material through approved handling. Assign ownership for the shared storage and certificate installation on each node. Maintain an alternative management route during the change and agree on the conditions that require stopping the rollout.\nVerification\nVerify the resulting gateway version, active instance, certificate presentation, and access to an intended managed server. Exercise the agreed node failover and confirm management resumes through the expected gateway name. Record any configuration that required restoration or recreation before accepting the upgraded highly available deployment.\nOfficial references\nMicrosoft Learn: Deploy Windows Admin Center with High Availability. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:13+00:00",
                "dateModified": "2026-09-08T18:29:34+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Plan the WAC high-availability transition across the 2410 architecture change"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 218,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Deploy Windows Admin Center with High Availability",
                    "url": "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability"
                }
            }
        ]
    }
}