How to Restrict Access to Windows Admin Center?

Your network contains an Active Directory Domain Services (AD DS) domain. The domain contains a server named Server1. On Server1, you install Windows Admin Center and use Windows Admin Center to remove BUILTIN\Users from the allowed groups. You discover that all users can still sign in to Windows Admin Center. You need to prevent unauthorized users from signing in to Windows Admin Center. What should you do in Windows Admin Center?

  1. Set Performance Profile to On.
  2. Set Require manage-as sessions to re-authenticate to On.
  3. From the Proxy settings, configure a bypass list.
  4. Add a security group to the allowed groups. Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of Windows Admin Center's explicit allow-list access model, where the common trap is assuming removing default user groups automatically restricts access.

Restricting access to Windows Admin Center requires explicitly assigning authorized security groups to the allowed groups list. Community consensus confirms that merely removing default groups like BUILTIN\Users is insufficient without adding a specific group.

Community Discussion (4 comments)

stonwall12 👍 1 Selected: D
Answer: D, security group After removing BUILTIN\Users, you must add a specific security group to the allowed groups list. Without adding an allowed group, Windows Admin Center defaults to allowing all users despite removing BUILTIN\Users. Adding a security group provides proper access control. Reference: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options
Krayzr 👍 1 Selected: D
By adding a specific security group to the allowed groups, you can control which users have access to Windows Admin Center. This ensures that only authorized users within that security group can sign in https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options
Ni_yot 👍 2 Selected: D
there are a number of ways Windows Admin Center can be secured - https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/plan/user-access-options
Ksk08 👍 3
Answer should be D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Windows Admin Center utilizes an explicit allow-list architecture for authentication and authorization. Simply removing the default BUILTIN\Users group does not enable a deny-all policy; it merely removes that specific group from the whitelist. To enforce strict access control, administrators must explicitly add a targeted security group to the allowed groups configuration, ensuring only authorized identities can authenticate.

Why the Other Options Are Wrong

Option A configures performance optimization settings that affect UI responsiveness and resource consumption, not authentication. Option B controls credential elevation behavior for administrative tasks rather than initial console sign-in restrictions. Option C manages network routing rules for proxy connections and has zero impact on user access policies or identity verification within the application.

Community Comment Notes

The community unanimously selected option D, highlighting that explicit group assignment is mandatory after deleting defaults. Commenters referenced official Microsoft documentation detailing user access options, reinforcing that WAC defaults to permissive access unless a specific group is whitelisted. Multiple votes confirmed this behavior aligns with real-world deployment scenarios and exam objectives.

Official Reference

Exam Strategy

Focus on understanding explicit allow-list versus implicit deny models in modern Windows management tools. When configuring admin consoles, always verify how default permissions are evaluated and ensure authorized groups are explicitly added after modifying baseline configurations.

Related Analysis

← Back to AZ-800 Study Guide