MicrosoftDocs / Windows-Admin-Center-Ideas-and-Feedback

Windows Admin Center's hub for ideas and feedback.
Creative Commons Attribution 4.0 International
20 stars 9 forks source link

Windows Admin Center on Domain Controller - Plans and related security issues #293

Open shiroinekotfs opened 5 months ago

shiroinekotfs commented 5 months ago

Windows Admin Center (formerly Project Honolulu) is one of the essential tools for managing Windows Server infrastructure and overall IaaS management tools. However, it seems like WAC cannot be installed on Domain Controler, as Microsoft claimed:

Installing Windows Admin Center on a Domain controller is not supported. Read more about domain controller security best practices.

Why installing Windows Admin Center on Domain Controller is essential?

Windows Admin Center isn't just a suitable tool for managing gateways, especially domain controllers. It helps reduce the managing costs, and minimal maintenance times, which is helping a lot in small and medium businesses - which roughly don't have many servers for running services.

For me, and maybe, hundreds of people out there, think the same way: Installing Windows Admin Center, but not other tools, is the best way to solve all, not only cost problems but also technical problems.

Current installation and security problem

In v1 (?) and Windows Admin Center (Modernized Gateway)

Basically, all installation problems are already mentioned in my original post on Microsoft Tech Community about how I can install WAC on Domain Controller.

:warning: Warning

Installing my modified WAC installer means you accepted the risk of opening the port, running for serving the Windows Admin Center. Please proceed with high caution.

Problems with the opening port and configuration in Windows Admin Center (Modernized Gateway)

In my suggestion, there are many ways to solve the risk of opening the WAC serving port, including:

Conclusion

I understand that this topic may be challenging for those in the Microsoft and cyber-security fields, but I am here to help us find a solution.

Hope @trungtran-msft will find a better way to solve this for me, and other Microsoft customers. I don't want to buy/subscribe 3rd party software anymore.

Although Azure Arc is a good tool, it is not as powerful as on-premises tools.😊