# Design the access path for a dedicated WAC gateway in Azure

> What should be reviewed before hosting a Windows Admin Center gateway on an Azure VM?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-214-design-the-access-path-for-a-dedicated-wac-gateway-in-azure/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:37+00:00
- Modified: 2026-09-08T18:29:33+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

What should be reviewed before hosting a Windows Admin Center gateway on an Azure VM?

## Potentially affected

Administrators deploying an Azure-hosted Windows Admin Center gateway to manage multiple VMs.

## DSE recommendation

Prepare the resource, certificate, and network-access plan before running a deployment script.

## Article

## Source facts

Microsoft distinguishes deploying a dedicated WAC gateway on an Azure VM for multiple VMs from using the portal experience for one VM. Its deployment script can create the environment, including the resource group. The documented gateway needs HTTPS access on port 443. Microsoft recommends limiting self-signed gateway certificates to test environments. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/deploy-wac-in-azure).

## Applicability

Choose the dedicated-gateway deployment deliberately and identify its intended operators and managed machines. Review the current script parameters, certificate guidance, and network requirements. Keep a gateway VM deployment separate from enabling the portal extension on an individual server.

## DSE recommendation

Prepare the resource, certificate, and network-access plan before running a deployment script. Have the Azure owner review every resource the selected parameters may create and the scope of allowed HTTPS clients. Assign an owner for the gateway name and certificate renewal. Use a controlled pilot and retain a documented management alternative while the gateway is being introduced.

## Verification

Verify the created resources against the approved plan and connect using the intended DNS name and trusted certificate. Test one authorized managed VM and an unauthorized gateway user. Review the actual network exposure and any unexpected created resource. Accept the gateway only after its management path and operational ownership are clear.

## Official references

[Microsoft Learn: Deploy a Windows Admin Center gateway in Azure](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/deploy-wac-in-azure). Source reviewed September 8, 2026.

## Primary reference

- Name: Deploy a Windows Admin Center gateway in Azure
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/azure/deploy-wac-in-azure
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Design the access path for a dedicated WAC gateway in Azure,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-214-design-the-access-path-for-a-dedicated-wac-gateway-in-azure/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
