Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Someone needs to check a Server Core box, and nobody wants to RDP in or remember which MMC snap-in does what. Microsoft's answer is a browser tab that talks to your servers for you. Here's what Windows Admin Center does, how to install and secure it, and where it stops being the right tool.

What Is Windows Admin Center?

Windows Admin Center (WAC) is Microsoft's free, browser-based console for managing Windows Server, clusters and Windows clients. Microsoft describes it as the modern evolution of in-box tools like Server Manager and MMC. It ships with your Windows Server license at no extra cost.

It runs locally. You install it on a PC or a server inside your network, and it manages machines that never touch the internet. That makes it useful for air-gapped sites and Server Core installs with no desktop.

Microsoft is clear about its scope: WAC is built for managing a single server or cluster in depth. It complements System Center, RSAT and Intune. It doesn't replace them.

How the Gateway Works

Every WAC install has two parts. Your browser, and a gateway service that does the work. The gateway connects to each managed machine with Remote PowerShell and WMI over WinRM, runs the commands, and turns the results into the pages you see.

Version 2410 rebuilt that gateway. It moved the backend from .NET 4.6.2 to .NET 8, swapped the old Katana web server for ASP.NET Core Kestrel, and added HTTP/2. It also split the single gateway process into a process manager that starts subprocesses per task. Microsoft calls this the modernized gateway.

Releases since then: 2511 restored high availability, which 2410 had dropped, and 2606 is the current generally available version per Microsoft's release history (updated July 2026). Each non-preview version is supported until 30 days after the next one ships, so plan updates, not one-off installs.

Because everything rides on WinRM, the targets need it enabled and reachable (port 5985, or 5986 for HTTPS). Servers running 2012 or 2012 R2 also need Windows Management Framework 5.1. Our list of PowerShell commands covers the remoting cmdlets WAC relies on under the hood.

Install Options: Local Client, Gateway or Cluster

Microsoft lists four ways to install it:

Install typeRuns onGood for
Local clientWindows 11One admin, quick start, testing
Gateway serverWindows Server 2016 to 2025A team sharing one URL
Managed serverA server you also manageDistributed or branch setups
Failover clusterA Windows Server clusterA gateway that survives a node failure

Two rules catch people out. WAC isn't supported on a domain controller. And Microsoft doesn't recommend managing the same server WAC is installed on; connect to it from another machine instead.

The installer offers Express setup or Custom setup. Express picks the port and network access for you. Custom lets you set the port, the TLS certificate, the gateway's FQDN, trusted hosts mode and WinRM over HTTPS. If you let the installer create a self-signed certificate, it expires after 60 days, so treat it as a lab option only.

On Server Core, the install is one line. Download the installer, then run it silently:

powershell
Start-Process -FilePath '.\WindowsAdminCenter.exe' -ArgumentList '/VERYSILENT' -Wait

Add /HTTPSPortNumber and /CertificateThumbprint to set the port and a certificate from your own CA in the same step. Greene Tech's walkthrough shows the desktop installer end to end:

What You Can Manage With It

Connect a server and you get most of what Server Manager and the MMC snap-ins do, in one place. Events, services, processes, storage, certificates, firewall rules, scheduled tasks, local users and Windows Update. There's a PowerShell console and a Remote Desktop tool in the browser too.

It goes further on Hyper-V and clusters. You can create and manage VMs, run failover clusters, and deploy and manage hyperconverged clusters with Storage Spaces Direct and software-defined networking. Windows 11 PCs show up through a Computer Management view.

Extensions fill gaps. Microsoft and hardware vendors publish them through the built-in feed, and Microsoft ships an SDK for building your own.

There's also a cloud-hosted flavour. Windows Admin Center in the Azure portal manages Azure VMs and, in preview, Azure Arc-enabled servers, without a VPN or inbound port on the machine.

When 2511 shipped, the r/sysadmin thread filled up with the wish list: the Active Directory tool still expects domain admin rights, and it won't connect from an Entra ID-joined machine.

Lock It Down: Access, Roles and Delegation

A WAC gateway is a single door into every server it can reach. Treat it like one.

Start with gateway access. WAC has two roles: gateway users, who can manage servers through it, and gateway administrators, who decide who gets in. Local administrators on the gateway machine are always gateway administrators. By default any user who can reach the URL gets in, so add a security group to the Users list on day one. You can require smartcards, or turn on Microsoft Entra ID as an extra layer to get MFA and conditional access.

Gateway access doesn't grant server access. Each user still needs admin rights on the target, or a role through role-based access control. RBAC installs a Just Enough Administration endpoint on the server with three local groups: Windows Admin Center Administrators, Hyper-V Administrators and Readers. It isn't supported for cluster management, so plan roles per server.

Single sign-on on a server gateway needs Kerberos delegation. Microsoft's example sets resource-based constrained delegation on each target:

powershell
Set-ADComputer -Identity (Get-ADComputer node01) -PrincipalsAllowedToDelegateToAccount (Get-ADComputer wac)

Finally, give the gateway a certificate from a trusted CA, publish it by FQDN, and keep it updated. Our Intune review covers the policy side WAC doesn't touch.

Why It Feels Slow, and What Helps

Ask r/sysadmin about WAC and speed comes up first. One admin timed a Hyper-V VM build at more than 30 minutes in WAC against about a minute in Failover Cluster Manager. The explanation in these threads is consistent: every page is PowerShell over WinRM, converted to JSON, then rendered in a browser. The MMC tools talk to services over RPC directly.

The same threads share what helped them. Connect to servers by FQDN rather than NetBIOS name, and use a trusted certificate rather than the self-signed one. One admin found antivirus scanning the WAC install folder slowed it to a crawl. Test any exclusion narrowly before rolling it out. Updating to the current release matters too, since 2410 and later run on the rebuilt .NET 8 gateway.

Where Windows Admin Center Stops

WAC is a remote hands tool, not a management platform. The limits show up fast once you manage more than a handful of servers.

It works one server or cluster at a time. There's no orchestration: you can't push a change to fifty machines in one action. Alerting and history exist only for hyperconverged clusters through the cluster health service. It isn't policy-driven, so drift between servers is yours to notice. And it assumes one trusted network per gateway. Microsoft notes that group-based access doesn't work across non-trusted domains or in workgroups.

That last point decides it for anyone running several clients or sites. Each client needs its own gateway, its own access groups and its own certificate. There's no single view across them, no ticketing, and no patch reporting across the estate. That's the gap an RMM platform fills: agents on every endpoint, policies, alerts and scripts across all clients at once. In OpenFrame, you can run the same PowerShell checks as scripts across a client's devices and collect the output in one place.

A practical split: keep WAC for deep, hands-on work on a Server Core host or a Hyper-V cluster. Use your RMM for fleet-wide patching, monitoring and scripting, and Intune for device policy. The WinRM setup WAC depends on is worth getting right on its own, and we're covering it in a separate guide.

The Short Version

Windows Admin Center is a free browser console for Windows Server, clusters and Windows 11. Install it on a dedicated gateway, never a domain controller, with a trusted certificate. Lock down gateway access with security groups and Entra ID, and use RBAC so techs don't need full admin. Expect it to be slower than the old snap-ins, and don't expect it to manage a fleet.

If you're deciding how WAC fits next to your other tools, start with what an RMM does that WAC doesn't.

Dmytro Koval

Dmytro Koval

Head of Product Engineering

Hi! My name is Dmytro, but everyone calls me Dima. I’m a Software Developer and together with the development team, I help bring Flamingo to life — putting it on its feet from a technical perspective. Originally from Lviv, Ukraine 🇺🇦, but currently based in Spain, where I’ve been enjoying the blend of great weather, culture, and nature. I’m passionate about the mountains and love traveling — exploring new places and cultures really inspires me. These experiences constantly recharge me and give me a fresh perspective, both personally and professionally.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Windows Admin Center

Windows Admin Center is a free, browser-based console for managing Windows Server, failover and hyperconverged clusters, Hyper-V and Windows 11 PCs. It covers most of what Server Manager and the MMC snap-ins do, such as events, services, storage, certificates, firewall rules and updates, and it works well for Server Core machines with no desktop.
Yes. Microsoft includes Windows Admin Center with a Windows Server license at no extra cost, and you download it from the Microsoft Evaluation Center. Each non-preview version is supported until 30 days after the next non-preview version is released, so plan to keep it updated.
No. Microsoft does not support installing Windows Admin Center on a domain controller. Install it on Windows 11 as a local client, or on Windows Server 2016 to 2025 as a gateway, and connect to the servers you manage from there.
Not for fleets. Windows Admin Center manages one server or cluster at a time, has no orchestration across machines, offers alerting only for hyperconverged clusters and needs a gateway per trusted domain. An RMM covers monitoring, patching and scripts across every endpoint and client, so the two work best side by side.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.