# Plan the WAC high-availability transition across the 2410 architecture change

> What deployment constraints apply when upgrading an older highly available WAC gateway?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:13+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

What deployment constraints apply when upgrading an older highly available WAC gateway?

## Potentially affected

Administrators upgrading Windows Admin Center gateways hosted in failover clusters.

## DSE recommendation

Have the gateway owner prepare the documented uninstall-and-reinstall transition in a representative cluster.

## Article

## Source facts

Microsoft describes the clustered WAC gateway as active-passive, with one active instance at a time. Its current guidance says highly available versions 2311 and earlier cannot directly upgrade to versions 2410 and later because of architectural changes. The documented high-availability prerequisites include shared persistent storage and the required certificate with its private key on every node. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability).

## Applicability

Identify the actual gateway version and deployment method before selecting an upgrade path. Review the current HA scripts and certificate requirements rather than using an ordinary single-server update procedure. Treat this transition as a deployment change with its own maintenance and recovery plan.

## DSE recommendation

Have the gateway owner prepare the documented uninstall-and-reinstall transition in a representative cluster. Preserve the current configuration and required recovery material through approved handling. Assign ownership for the shared storage and certificate installation on each node. Maintain an alternative management route during the change and agree on the conditions that require stopping the rollout.

## Verification

Verify the resulting gateway version, active instance, certificate presentation, and access to an intended managed server. Exercise the agreed node failover and confirm management resumes through the expected gateway name. Record any configuration that required restoration or recreation before accepting the upgraded highly available deployment.

## Official references

[Microsoft Learn: Deploy Windows Admin Center with High Availability](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability). Source reviewed September 8, 2026.

## Primary reference

- Name: Deploy Windows Admin Center with High Availability
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/deploy/high-availability
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Plan the WAC high-availability transition across the 2410 architecture change,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-238-plan-the-wac-high-availability-transition-across-the-2410-architecture-change/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
