How to Restrict Access to Windows Admin Center?
Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1. On Server1, you install Windows Admin Center and use Windows Admin Center to remove BUILTIN\Users from the allowed groups. You discover that all users can still sign in to Windows Admin Center. You need to prevent unauthorized users from signing in to Windows Admin Center. What should you do in Windows Admin Center?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of Windows Admin Center's explicit allow-list access model, where the common trap is assuming removing default user groups automatically restricts access.
Restricting access to Windows Admin Center requires explicitly assigning authorized security groups to the allowed groups list. Community consensus confirms that merely removing default groups like BUILTIN\Users is insufficient without adding a specific group.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Windows Admin Center utilizes an explicit allow-list architecture for authentication and authorization. Simply removing the default BUILTIN\Users group does not enable a deny-all policy; it merely removes that specific group from the whitelist. To enforce strict access control, administrators must explicitly add a targeted security group to the allowed groups configuration, ensuring only authorized identities can authenticate.Why the Other Options Are Wrong
Option A configures performance optimization settings that affect UI responsiveness and resource consumption, not authentication. Option B controls credential elevation behavior for administrative tasks rather than initial console sign-in restrictions. Option C manages network routing rules for proxy connections and has zero impact on user access policies or identity verification within the application.Community Comment Notes
The community unanimously selected option D, highlighting that explicit group assignment is mandatory after deleting defaults. Commenters referenced official Microsoft documentation detailing user access options, reinforcing that WAC defaults to permissive access unless a specific group is whitelisted. Multiple votes confirmed this behavior aligns with real-world deployment scenarios and exam objectives.Official Reference
Exam Strategy
Focus on understanding explicit allow-list versus implicit deny models in modern Windows management tools. When configuring admin consoles, always verify how default permissions are evaluated and ensure authorized groups are explicitly added after modifying baseline configurations.