Windows Admin Center Secured-core server view
The latest Windows Admin Center (WAC) release, version 2511 (November 2025, public preview), introduces refreshed management tools and deeper integration with modern Windows security features like Secure Boot, TPM 2.0, Kernel DMA Protection, Virtualization‑based Security (VBS), and OSConfig baselines for Windows Server.
Secured-core is a collection of capabilities that offers built-in hardware, firmware, driver and operating system security features. The protection provided by Secured-core systems begins before the operating system boots and continues whilst running. Secured-core server is designed to deliver a secure platform for critical data and applications.
Secured-core server is built on three key security pillars:
- Creating a hardware backed root of trust.
- Defense against firmware level attacks.
- Protecting the OS from the execution of unverified code.
Windows Admin Center 2511: Security Meets Modern Management
Windows Admin Center has steadily evolved into the preferred management platform for Windows Server and hybrid environments. With the 2511 build now in public preview, Microsoft continues to refine the experience for IT administrators, blending usability improvements with defense‑in‑depth security Microsoft Community.
Security Features at the Core ✅
What makes this release stand out is how WAC aligns with the latest Windows security stack. Let’s break down the highlights:
- OSConfig Security Baselines
WAC now integrates baseline enforcement, ensuring servers adhere to CIS Benchmarks and DISA STIGs. Drift control automatically remediates deviations, keeping configurations locked to secure defaults. ( I like this one!) - Hardware‑based Root of Trust
Through TPM 2.0 and System Guard, WAC can validate boot integrity. This means admins can remotely attest that servers started securely, free from tampering. - Kernel DMA Protection
Thunderbolt and USB4 devices are notorious vectors for DMA attacks. WAC surfaces configuration and compliance checks, ensuring IOMMU‑based protection is active. - Secure Boot Management
OEM Secure Boot policies are visible and manageable, giving admins confidence that only signed, trusted firmware and drivers load during startup. - Virtualization‑based Security (VBS)
WAC exposes controls for enabling VBS and Memory Integrity (HVCI). These features isolate sensitive processes in a hypervisor‑protected environment, blocking unsigned drivers and kernel exploits.
Windows Server security baseline not yet implemented as you can see 😉
What’s New in Build 2511
Beyond security, version 2511 delivers refinements to the virtual machines tool, installer improvements, and bug fixes. Combined with the backend upgrade to .NET 8 in the earlier 2410 GA release, WAC is faster, more reliable, and better equipped for enterprise workloads.
Why It Matters
In today’s hybrid IT landscape, security and manageability must coexist. Windows Admin Center 2511 demonstrates Microsoft’s commitment to:
- Unified management: One pane of glass for servers, clusters, and Azure Arc‑connected resources.
- Compliance assurance: Built‑in baselines reduce audit headaches.
- Future‑proof security: Hardware‑rooted trust and virtualization‑based isolation protect against evolving threats.
Final Thoughts
If you’re an IT admin preparing for Windows Server 2025 deployments, the new Windows Admin Center build is more than just a management tool—it’s a security enabler. By weaving in Secure Boot, TPM, DMA protection, and VBS, WAC ensures that your infrastructure isn’t just easier to manage, but fundamentally harder to compromise.
Here you find the Microsoft docs :
What is Secured-core server for Windows Server | Microsoft Learn
OSConfig overview for Windows Server | Microsoft Learn
How System Guard helps protect Windows | Microsoft Learn
Kernel DMA Protection | Microsoft Learn
Trusted Plaform Module (TPM) 2.0 | Microsoft Learn
Virtualization-based Security (VBS) | Microsoft Learn
Enable memory integrity | Microsoft Learn
What is Windows Admin Center Virtualization Mode (Preview)?
Windows Admin Center Virtualization Mode is a purpose-built management experience for virtualization infrastructure. It enables IT professionals to centrally administer Hyper-V hosts, clusters, storage, and networking at scale.
Unlike administration mode, which focuses on general system management, Virtualization Mode focuses on fabric management. It supports parallel operations and contextual views for compute, storage, and network resources. This mode is optimized for large-scale, cluster-based environments and integrates lifecycle management, global search, and role-based access control.
Virtualization Mode offers the following key capabilities:
- Search across navigation objects with contextual filtering.
- Support for SAN, NAS, hyperconverged, and scale-out file server architectures.
- VM templates, integrated disaster recovery with Hyper-V Replica, and onboarding of Arc-enabled resources (future capability).
- Software-defined storage and networking (not available at this time).
Install Windows Admin Center Virtualization Mode
Test all these New features of Windows Admin Center and Windows Server in your test environment and be ready for production when it becomes general available. Download Windows Admin Center 2511 Preview here



















































































