Windows Admin Center - how to publish WAC console through AppProxy/MFA and use all functionalities

%3CLINGO-SUB%20id%3D%22lingo-sub-1770876%22%20slang%3D%22en-US%22%3EWindows%20Admin%20Center%20-%20how%20to%20publish%20WAC%20console%20through%20AppProxy%2FMFA%20and%20use%20all%20functionalities%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1770876%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20an%20on%20prem%20server%20win%20WAC%20console%20installed.%3C%2FP%3E%3CP%3EI%E2%80%99d%20like%20to%20use%20WAC%20via%20Azure%20AppProxy%2C%20so%20I%20can%20connect%20to%20WAC%20from%20external%20network%20via%20AppProxy%2FMFA%20and%20remotely%20manage%20my%20environment%2Fsystems%20remotely%20via%20Powershell%2C%20and%20Remote%20desktop%20as%20well.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%2C%20it%20seems%20doesn't%20work%20because%20%22Remote%20Desktop%2C%20PowerShell%2C%20and%20Events%20modules%20in%20Windows%20Admin%20Center%20utilize%20the%20WebSocket%20protocol%2C%20which%20is%20often%20not%20supported%20when%20using%20a%20proxy%20service.%22%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Fsupport%2Fknown-issues%23websocket-compatibility-when-using-a-proxy-service%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Fsupport%2Fknown-issues%23websocket-compatibility-when-using-a-proxy-service%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20If%20I%20would%20like%20to%20remotely%20connect%20to%20WAC%20console%20in%20a%20safe%20manner%20(with%20Azure%20MFA)%20and%20use%20all%20functionalities%20(RDP%20and%20powershell%20remotely)%20which%20is%20the%20best%20practices%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20case%20opened%20for%20this%2C%20but%20I'm%20still%20waiting%20an%20answer%20from%20Product%20team.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethank%20you%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1788701%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Admin%20Center%20-%20how%20to%20publish%20WAC%20console%20through%20AppProxy%2FMFA%20and%20use%20all%20functionaliti%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1788701%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F538511%22%20target%3D%22_blank%22%3E%40Chris81%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eplease%20have%20a%20look%20here%20-%20you%20will%20need%20a%20Windows%20Admin%20Center%20gateway%20server%20which%20you%20must%20publish%20to%20the%20internet%20(classic%20port%20forwarding)%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fde-de%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Fplan%2Finstallation-options%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fde-de%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Fplan%2Finstallation-options%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20integrate%20the%20gateway%20with%20Azure%20authentication%20as%20shown%20here%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fde-de%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Fazure%2Fazure-integration%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fde-de%2Fwindows-server%2Fmanage%2Fwindows-admin-center%2Fazure%2Fazure-integration%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

I have an on prem server win WAC console installed.

I’d like to use WAC via Azure AppProxy, so I can connect to WAC from external network via AppProxy/MFA and remotely manage my environment/systems remotely via Powershell, and Remote desktop as well.

 

Unfortunately, it seems doesn't work because "Remote Desktop, PowerShell, and Events modules in Windows Admin Center utilize the WebSocket protocol, which is often not supported when using a proxy service."

https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/support/known-issues#web... 

 

So, If I would like to remotely connect to WAC console in a safe manner (with Azure MFA) and use all functionalities (RDP and powershell remotely) which is the best practices?

 

I have a case opened for this, but I'm still waiting an answer from Product team.

 

thank you

 

2 Replies

Hi @Chris81,

 

please have a look here - you will need a Windows Admin Center gateway server which you must publish to the internet (classic port forwarding): https://docs.microsoft.com/de-de/windows-server/manage/windows-admin-center/plan/installation-option...

 

You can integrate the gateway with Azure authentication as shown here:

https://docs.microsoft.com/de-de/windows-server/manage/windows-admin-center/azure/azure-integration 

@Chris81,

Did you ever get a response from the Product Team?

@BenKrah response doesn't really provide the security and controls that Auzre AppProxy does, and to me this seems like a great use case - independent of if you are authenticating to WAC with local, Windows Active Directory, or Azure AD (Cloud-only or Hybrid).
www.000webhost.com