IIS Server Security - IIS User Right

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > February 2006 > IIS User Right





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author IIS User Right
Felix

2006-02-07, 6:02 pm

On the IIS (Windows Server 2003) I have a website wich allows anonymous
access and basic authenification. For one directory on this website I
disabled the anonymous access and in the directory security I refuse the
right to the IIS guest account. Now, like I wanted to be, a user has to sign
in, before reading the content of this directory. But every user with an
account in the domain can log in although only administrators, interactive,
network, network service has rights to access read the directory. What did I
wrong? I only want to give specific users the right to read this
web-directory. Many thanks for your help!
Tom Kaminski [MVP]

2006-02-07, 6:02 pm

"Felix" <fst@newsgroups.nospam> wrote in message
news:2684419D-D173-495B-BB91-063F00B483A0@microsoft.com...
> On the IIS (Windows Server 2003) I have a website wich allows anonymous
> access and basic authenification. For one directory on this website I
> disabled the anonymous access and in the directory security I refuse the
> right to the IIS guest account. Now, like I wanted to be, a user has to
> sign
> in, before reading the content of this directory. But every user with an
> account in the domain can log in although only administrators,
> interactive,
> network, network service has rights to access read the directory. What did
> I
> wrong? I only want to give specific users the right to read this
> web-directory. Many thanks for your help!


What other NTFS permissions are assigned to the folder?

--
Tom Kaminski IIS MVP
http://www.microsoft.com/windowsser...ty/centers/iis/
http://mvp.support.microsoft.com/
http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS


Miha Pihler [MVP]

2006-02-07, 6:02 pm

Hi,

IIS will always honor the NTFS permissions. If you set permissions right
only users that you set up will have access to that folder (I guess your
users still inherit read permissions from somewhere)...

My suggestion would be to create new group and allow this group read access
(or some other permission if this group of users need it). Now remove all
other groups and users permissions from this folder (except maybe
Administrators if you want to allow them access to the files).

--
Mike
Microsoft MVP - Windows Security

"Felix" <fst@newsgroups.nospam> wrote in message
news:2684419D-D173-495B-BB91-063F00B483A0@microsoft.com...
> On the IIS (Windows Server 2003) I have a website wich allows anonymous
> access and basic authenification. For one directory on this website I
> disabled the anonymous access and in the directory security I refuse the
> right to the IIS guest account. Now, like I wanted to be, a user has to
> sign
> in, before reading the content of this directory. But every user with an
> account in the domain can log in although only administrators,
> interactive,
> network, network service has rights to access read the directory. What did
> I
> wrong? I only want to give specific users the right to read this
> web-directory. Many thanks for your help!



Felix

2006-02-07, 6:02 pm

NTFS Permissions are set to administrators, IIS_WPG, interactive, Network,
Network Service AND System with full access and the IUSR_IIS1 all denied.

"Tom Kaminski [MVP]" wrote:

>
> What other NTFS permissions are assigned to the folder?
>
> --
> Tom Kaminski IIS MVP
> http://www.microsoft.com/windowsser...ty/centers/iis/
> http://mvp.support.microsoft.com/
> http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS
>
>
>

Felix

2006-02-07, 6:02 pm

The only NTFS Permissions are set to administrators, IIS_WPG, interactive,
Network, Network Service AND System with full access and the IUSR_IIS1 all
denied.

"Miha Pihler [MVP]" wrote:

> Hi,
>
> IIS will always honor the NTFS permissions. If you set permissions right
> only users that you set up will have access to that folder (I guess your
> users still inherit read permissions from somewhere)...
>
> My suggestion would be to create new group and allow this group read access
> (or some other permission if this group of users need it). Now remove all
> other groups and users permissions from this folder (except maybe
> Administrators if you want to allow them access to the files).
>
> --
> Mike
> Microsoft MVP - Windows Security
>

Miha Pihler [MVP]

2006-02-07, 6:02 pm

Hi,

As suggested. Remove everything but Administrators and your new group that
will contain users that are allowed to have access to this site.

--
Mike
Microsoft MVP - Windows Security

"Felix" <fst@newsgroups.nospam> wrote in message
news:FB51428B-55DC-4FC1-A547-4FAE764CC7B4@microsoft.com...[vbcol=seagreen]
> The only NTFS Permissions are set to administrators, IIS_WPG, interactive,
> Network, Network Service AND System with full access and the IUSR_IIS1 all
> denied.
>
> "Miha Pihler [MVP]" wrote:
>


Yuan Ren[MSFT]

2006-02-08, 3:00 am

Hi,

Thanks for posting!

For the current issue, as Tom and Mike mentioned, the permission for the
IIS is depended on the NTFS permission settings for the current folder. I
suggest you remove the IIS_WPG and Network Service account and add the user
account which is allowed to access the current folder. So, the other users
can not access the current folder since they don't have permission.

Thanks for your understanding!

Regards,

Yuan Ren [MSFT]
Microsoft Online Support

Tom Kaminski [MVP]

2006-02-09, 7:55 am

""Yuan Ren[MSFT]"" <v-yren@microsoft.com> wrote in message
news:mPP$82FLGHA.768@TK2MSFTNGXA01.phx.gbl...
> Hi,
>
> Thanks for posting!
>
> For the current issue, as Tom and Mike mentioned, the permission for the
> IIS is depended on the NTFS permission settings for the current folder. I
> suggest you remove the IIS_WPG and Network Service account and add the
> user
> account which is allowed to access the current folder. So, the other users
> can not access the current folder since they don't have permission.


Additionally, I prefer to not even list IUSR when I want to deny anonymous
access.


Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com