Skip to main content
Version: Next

Task 05: Configure Windows Admin Center

Runbook Azure

DOCUMENT CATEGORY: Runbook SCOPE: Windows Admin Center installation and configuration PURPOSE: Establish web-based management portal for Azure Local cluster operations MASTER REFERENCE: Microsoft Learn - WAC

Status: Active


Overview

Windows Admin Center (WAC) provides a web-based management interface for Azure Local clusters. It is installed on the utility server and used for cluster health monitoring, VM management, storage operations, and Azure hybrid integration.

Task Classification

Execution Target: Windows Server (on-VM configuration) Tab Profile: 4 tabs — WAC Web UI · Direct Script (On Node) · Orchestrated Script (Mgmt Server) · Standalone Script

Configuration Summary

SettingValueSource
Install TargetUtility Serverazure_vms.utility.name
WAC Port443 (HTTPS)Default
WAC URLhttps://util-eus-01.azrl.mgmtazure_vms.utility.fqdn
CertificateSelf-signed (initial)Auto-generated
VersionLatest stableMicrosoft Download Center

Required WAC Extensions

ExtensionPurpose
Cluster ManagerAzure Local cluster management
Azure Hybrid CenterAzure Arc and hybrid integration
Azure MonitorMonitoring integration
Virtual MachinesVM lifecycle management
StorageStorage pool and volume management
NetworkingSDN and network management

Prerequisites

  • Task 02: Configure Utility Server completed — utility VM domain-joined
  • Internet access for WAC download (NAT Gateway — Task 07)
  • Utility VM accessible via Bastion
  • Domain admin credentials for extension installation

Variables from variables.yml

VariableConfig PathExample (IIC)
Utility VM Nameazure_vms.utility.namevm-util-azl-eus-01
Utility VM FQDNazure_vms.utility.fqdnutil-eus-01.azrl.mgmt
Cluster Namecluster.deployment.cluster_nameazl-demo-clus01

Single Subscription Model

Landing Zone Placement

FieldValueConfig Path
Install TargetUtility Serverazure_vms.utility
Access URLhttps://<utility_fqdn>azure_vms.utility.fqdn
Cluster to ManageAzure Local clustercluster.deployment.cluster_name

Execution Options

WAC Web UI

When to use: Standard installation via GUI installer on the utility server

Procedure — Download and Install

  1. Connect to utility VM via Bastion (Task 05)

  2. Download WAC:

  1. Run MSI installer: | Setting | Value | |---------|-------| | Port | 443 | | Use WinRM (HTTPS) | Checked | | Generate self-signed cert | Checked | | Allow WAC to modify TrustedHosts | Checked |

  2. Complete installation — WAC service starts automatically

Procedure — Initial Configuration

  1. Access WAC: Open https://localhost on the utility server

  2. Add Cluster Connection:

  • Click AddServer clusters
  • Cluster name: From cluster.deployment.cluster_name
  • Credentials: Use domain admin
  1. Install Extensions:
  • Navigate to SettingsExtensions
  • Install or update:
  • Cluster Manager
  • Azure Hybrid Center
  • Azure Monitor
  • Virtual Machines
  • Storage
  • Networking

Procedure — Azure Integration

  1. Register WAC with Azure:
  • Settings → AzureRegister
  • Sign in with Azure AD credentials
  • Select the management subscription
  • Grant required permissions
  1. Enable Azure Monitor:
  • Cluster → Azure Monitor → Enable
  • Select Log Analytics workspace: log-azrlmgmt-azl-eus-01 (azure_infrastructure.log_analytics.workspace_name)

Validation

  • WAC accessible at https://util-eus-01.azrl.mgmt
  • Cluster connection healthy — green status
  • All extensions installed and current
  • Azure registration complete
  • Azure Monitor forwarding data

Validation

  • WAC service running: Get-Service ServerManagementGateway
  • Web UI accessible: https://util-eus-01.azrl.mgmt
  • Cluster connection established
  • Extensions installed and current version
  • Azure registration completed

CAF/WAF Landing Zone Model

WAC configuration is identical regardless of landing zone model — it runs on the utility VM in the Management subscription.

Landing Zone Placement

FieldValueConfig Path
SubscriptionManagement subscriptionazure.subscriptions.management.id
Install TargetUtility VM in Management spokeazure_vms.utility

Execution Options

The execution is the same as Single Subscription — WAC runs on the utility VM regardless of which subscription it resides in. The cluster connection points to the Azure Local cluster in its respective subscription.

Additional Considerations

In the CAF/WAF model, when registering WAC with Azure:

  • Use the Management subscription for WAC registration
  • The cluster may reside in a Workload subscription — cross-subscription access requires appropriate RBAC

Troubleshooting

IssueRoot CauseRemediation
MSI download failsNo internetVerify NAT Gateway (Task 07) and DNS
WAC service not startingPort conflictCheck if IIS or other service uses port 443
Cannot connect to clusterCredSSP/KerberosEnable CredSSP or use constrained delegation
Azure registration failsMissing permissionsEnsure Global Admin or App Administrator role
Extensions fail to installWAC version mismatchUpdate WAC to latest version first
Certificate warningSelf-signed certExpected for initial setup — replace with CA cert in production
Slow performanceLow VM resourcesVerify utility VM size is adequate

PreviousUpNext
Task 04: Lighthouse ServerVM Configuration

Version Control

  • Created: 2025-09-15 by Hybrid Cloud Solutions
  • Last Updated: 2026-03-20 by Hybrid Cloud Solutions
  • Version: 5.0.0
  • Tags: azure-local, wac, windows-admin-center, management, monitoring
  • Keywords: WAC, Windows Admin Center, cluster management, Azure integration, extensions
  • Author: Hybrid Cloud Solutions