AZ-802 Secure Windows Server Infrastructure Practice Question
You are securing Windows Admin Center (WAC) to manage your Windows Server 2022 environment. You want to implement granular access control for different IT teams. Which TWO methods can be used to control who has access to Windows Admin Center and what they can do? (Select TWO)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Active Directory groups for gateway access control.
Windows Admin Center security is managed through two main layers: gateway access and tool access. Gateway access is controlled via local groups or Active Directory groups on the WAC server. For more granular control over specific server tasks, WAC integrates with Just Enough Administration (JEA) to limit the cmdlets and actions available to the user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Active Directory groups for gateway access control.
Why this is correct
You can define which users or groups are allowed to log into the Windows Admin Center gateway by configuring the 'Users' and 'Administrators' settings. By using Active Directory groups, you can centrally manage who has the right to access the WAC interface and perform management tasks across the fleet.
- ✓
Just Enough Administration (JEA) for granular tool-level access.
Why this is correct
Windows Admin Center can leverage JEA to restrict the administrative actions a user can perform on a managed server. By assigning JEA endpoints, you ensure that even if a user can log into WAC, they can only use specific tools and run specific commands that have been explicitly permitted.
- ✗
Azure Key Vault for storing the WAC login credentials.
Why it's wrong here
While Azure Key Vault is excellent for managing secrets, Windows Admin Center primarily uses the user's own credentials (via Kerberos or CredSSP) or stored credentials within its own local configuration. It does not use Azure Key Vault as a primary mechanism for controlling user-level access permissions to the management console itself.
- ✗
NTFS permissions on the Windows Admin Center installation folder.
Why it's wrong here
NTFS permissions on the application folders control who can modify the WAC software files on the disk, but they do not control the logical access of users connecting to the web interface. WAC security is handled at the application level through its configuration settings and the underlying Windows authentication mechanisms.
- ✗
DHCP Reservations for the WAC gateway IP address.
Why it's wrong here
DHCP reservations ensure that the WAC server always receives the same IP address from the network. While this is helpful for ensuring the management console remains reachable at a consistent URL, it provides no security or access control benefits regarding which administrators are authorized to use the tool to manage servers.
About these practice questions
One of 116 original AZ-802 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-802 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-802 exam.