# Replace the Windows Admin Center HTTPS certificate deliberately

> What must be checked before a replacement certificate is selected for Windows Admin Center?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:11+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What must be checked before a replacement certificate is selected for Windows Admin Center?

## Potentially affected

Administrators maintaining the HTTPS certificate used by a Windows Admin Center gateway.

## DSE recommendation

Prepare the replacement against the gateway name, intended client trust, validity period, and private-key requirement.

## Article

## Source facts

Windows Admin Center requires an HTTPS certificate for its service. Microsoft requires a valid certificate with Server Authentication usage, a private key, and a name matching the gateway FQDN or IP address; its issuer must be trusted by the gateway and clients. The documented subject-name selection method requires a unique certificate subject name in the local-machine Personal certificate store. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate).

## Applicability

Identify the gateway address administrators actually use and the certificate-selection method for the installed version. Review the public certificate properties without exporting its private key. A successful certificate import is only one part of this replacement decision.

## DSE recommendation

Prepare the replacement against the gateway name, intended client trust, validity period, and private-key requirement. Where selection uses a subject name, inspect the relevant store for ambiguous matches before proceeding. Schedule the change with another management route available. Keep the previous certificate available under approved retention and key-handling rules until the replacement has passed the agreed connection checks.

## Verification

Connect from an intended administrator browser using the normal gateway URL. Inspect the certificate actually presented, its name and trust chain, and then open a managed connection. If an error remains, review Windows Admin Center events alongside the browser error and record which certificate was selected.

## Official references

[Microsoft Learn: Update the certificate used by Windows Admin Center](https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate). Source reviewed September 8, 2026.

## Primary reference

- Name: Update the certificate used by Windows Admin Center
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/update-certificate
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Replace the Windows Admin Center HTTPS certificate deliberately,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-240-replace-the-windows-admin-center-https-certificate-deliberately/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
