GuideInformationBusiness ContinuityIT

Separate Windows Admin Center gateway users from gateway administrators

Who should be able to use a WAC gateway and who should change its access policy?

A controlled technology lifecycle progressing from assessment to approved production.
DSE visual intelligenceManaged IT operationsGuide · 2 min read
Executive summary

What you need to know

Who should be able to use a WAC gateway and who should change its access policy?

Potentially affected

Administrators assigning Windows Admin Center gateway access permissions.

DSE recommendation

Create a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration.

Source facts

Microsoft says gateway users can use the WAC gateway to manage servers but cannot change its access permissions or authentication mechanism. The documented default access model uses Active Directory or local machine groups. When Entra authentication is selected, the page directs administrators to manage WAC user and administrator access permissions through the Azure portal. Microsoft Learn.

Applicability

Identify the deployed gateway access model and the groups currently assigned to its roles. Separate permission to use the gateway from authority to change the gateway’s own access policy. Review the managed servers’ permissions independently before interpreting a gateway role as complete task authorization.

DSE recommendation

Create a named role-assignment register with a business owner for gateway users and a smaller set responsible for access administration. Have a second administrator review broad or inherited group memberships. Preserve the current assignments and pilot a representative operator account. Include the procedure for removing an operator who changes duties and for recovering access if the role configuration is mistaken.

Verification

Verify that an approved gateway user can enter the gateway but cannot alter access settings. Test an excluded identity and confirm that the authorized administrator can review the assignments. Record the interface used to manage permissions and the resulting membership. Keep server-task authorization results as separate evidence.

Official references

Microsoft Learn: Configuring user access control and permissions. Source reviewed September 8, 2026.

Primary reference

Review the official source

Configuring user access control and permissions · Verified September 8, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE