# Separate Windows Admin Center gateway users from gateway administrators

> Who should be able to use a WAC gateway and who should change its access policy?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:32+00:00
- Modified: 2026-09-08T18:29:33+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Who should be able to use a WAC gateway and who should change its access policy?

## Potentially affected

Administrators assigning Windows Admin Center gateway access permissions.

## DSE recommendation

Create a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration.

## Article

## Source facts

Microsoft says gateway users can use the WAC gateway to manage servers but cannot change its access permissions or authentication mechanism. The documented default access model uses Active Directory or local machine groups. When Entra authentication is selected, the page directs administrators to manage WAC user and administrator access permissions through the Azure portal. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control).

## Applicability

Identify the deployed gateway access model and the groups currently assigned to its roles. Separate permission to use the gateway from authority to change the gateway’s own access policy. Review the managed servers’ permissions independently before interpreting a gateway role as complete task authorization.

## DSE recommendation

Create a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration. Have a second administrator review broad or inherited group memberships. Preserve the current assignments and pilot a representative operator account. Include the procedure for removing an operator who changes duties and for recovering access if the role configuration is mistaken.

## Verification

Verify that an approved gateway user can enter the gateway but cannot alter access settings. Test an excluded identity and confirm that the authorized administrator can review the assignments. Record the interface used to manage permissions and the resulting membership. Keep server-task authorization results as separate evidence.

## Official references

[Microsoft Learn: Configuring user access control and permissions](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control). Source reviewed September 8, 2026.

## Primary reference

- Name: Configuring user access control and permissions
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate Windows Admin Center gateway users from gateway administrators,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-219-separate-windows-admin-center-gateway-users-from-gateway-administrators/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
