Windows
 

Windows Server 2012 : Securing IIS 8 (part 3) - Creating an IIS 8 User Account, Assigning Permissions to an IIS 8 User Account

12/18/2013 1:53:58 AM

5. Administering IIS 8 Administrator and User Security

Administrative permissions for IIS 8 servers, websites, directory, applications and pages can be granted to Active Directory and to local Windows users. In addition, IIS specific accounts can be added and used for administration purposes. The use of Active Directory accounts is usually recommended as it is easier to manage and scales well when more than one or two IIS servers are used. Account and security management within IIS 8 requires installation of the Management Service role service.

6. Creating an IIS 8 User Account

In some situations, you might need to provide management capabilities and not want to use an Active Directory or Windows account. Examples of this scenario are often related to vendor support of an application. In this case, an IIS 8 user account is used. This IIS-only, non-Windows user can then be delegated permissions to manage components of the IIS infrastructure.

Follow these steps to enable support for IIS user accounts:

1. In IIS Manager, navigate to the Connections pane and select the IIS server.

2. Open the Management Service feature, which is located in the Central Details pane.

3. In the Identity Credentials section, select Windows Credentials or IIS Manager credentials.

4. Click Apply in the Action pane.

Follow these steps to create an IIS 8 user account:

1. In IIS Manager, navigate to the Connections pane and select the IIS server.

2. Open the IIS Manager Users feature, which is located in the Central Details pane.

3. On the IIS Manager Users feature page, click the Add User task, which is located in the Actions pane.

4. In the Add User dialog box, enter the new user account name and password, and then click OK.

For ongoing user account management, after the user account is created, use the additional tasks on the Actions pane to change the password, disable, or remove the account.

7. Assigning Permissions to an IIS 8 User Account

The next step in the user-creation process is to assign the appropriate permissions to the newly created user account. This process allows the user to configure delegated features for a specific website or application. Follow these steps to authorize a user account to connect to a site or an application:

1. In IIS Manager, navigate to the Connections pane, expand the IIS server, and then expand the Sites node.

2. Specify the site to which the user account will be granted authorization, and then open the IIS Manager Permissions feature, which is located in the Central Details pane.

3. On the IIS Manager Permissions feature page, click the Allow User task, which is located in the Actions pane.

4. In the Allow User dialog box, first select the IIS Manager option, then enter the account that was created in the previous steps, and then click OK.


Note

If the IIS Manager option is not available in the Allow User dialog box, the Management Service is not set to accept connections from IIS users. To do so, use the Management Service page to enable remote connections as outlined previously.

 
Others
 
- Windows Server 2012 : Securing IIS 8 (part 2) - Auditing Web Services , Using SSL Certificates
- Windows Server 2012 : Securing IIS 8 (part 1) - Windows Server 2012 Security, IIS Authentication
- Windows Small Business Server 2011 : Using Group Policy Results
- Windows Small Business Server 2011 : Group Policy Preferences (part 3) - Using Group Policy Preferences for Windows - Files
- Windows Small Business Server 2011 : Group Policy Preferences (part 2) - Using Group Policy Preferences for Windows - Drive Maps
- Windows Small Business Server 2011 : Group Policy Preferences (part 1)
- Windows Small Business Server 2011 : Deploying Applications with Group Policy (part 4) - Configuring the Group Policy Software Installation Extension - Adding a Software Package to a Group Policy
- Windows Small Business Server 2011 : Deploying Applications with Group Policy (part 3) - Configuring the Group Policy Software Installation Extension - Setting Software Installation Options
- Windows Small Business Server 2011 : Deploying Applications with Group Policy (part 2) - Creating a GPO for Software Deployment
- Windows Small Business Server 2011 : Deploying Applications with Group Policy (part 1) - Publish or Assign Applications , Creating a Software Distribution Point
- Windows Small Business Server 2011 : Using Group Policy - Backing Up a Group Policy Object, Restoring a Group Policy Object
- Windows Small Business Server 2011 : Using Group Policy - Refreshing Group Policy
- Windows Small Business Server 2011 : Managing Group Policy Links (part 2) - Enabling and Disabling GPO Links, Disabling a Branch of a GPO
- Windows Small Business Server 2011 : Managing Group Policy Links (part 1) - Setting the Scope of the GPO
- Windows Small Business Server 2011 : Using Group Policy - Creating a Group Policy Object
- Windows Server 2012 : Installing and Configuring FTP Services (part 6) - Configuring FTP 8 Features and Properties - FTP User Isolation Feature Page
- Windows Server 2012 : Installing and Configuring FTP Services (part 5) - Configuring FTP 8 Features and Properties - FTP Messages Feature Page, FTP Request Filtering
- Windows Server 2012 : Installing and Configuring FTP Services (part 4) - Configuring FTP 8 Features and Properties - FTP Directory Browsing Feature Page
- Windows Server 2012 : Installing and Configuring FTP Services (part 3) - Configuring FTP 8 Features and Properties - FTP Authentication Feature Page
- Windows Server 2012 : Installing and Configuring FTP Services (part 2) - Creating a Secure FTP 8 Site Using SSL
 
 
Most View
 
- Distributing Sharepoint 2013 Apps : Application Life Cycle - Using Seller Dashboard Metrics
- Microsoft Access 2010 : Relating the Information in Your Database - Establishing Relationships in Access
- Installing Exchange 2013 : Creating the Exchange 2013 organization
- Windows 7 : Configuring a High-Speed Connection (part 1) - Configuring a PPPoE Broadband Connection, Setting Up Dynamic IP Addressing
- Microsoft Lync Server 2013 : Director Overview (part 1) - Benefits of a Director - Internal Endpoint Sign-In Process
- SQL Server 2012 : Backing Up the Database (part 2) - Backing Up the Database with Code,Verifying the Backup with Code
- Microsoft Exchange Server 2013 : Creating special-purpose mailboxes (part 1) - Using room and equipment mailboxes
- SQL Server 2012 : Backup and Recovery Planning - Recovery Models (part 3) - Bulk-Logged Recovery Model, Setting the Recovery Model
- Windows 8 : Sharing and Securing with User Accounts - Creating and Using Password Reset Disks, Running Programs as Administrator
- Microsoft Exchange Server 2013 : Designing a Successful Exchange Storage Solution (part 2) - Making Sense of the Exchange Mailbox Server Role Requirements Calculator
 
 
Top 10
 
- Microsoft LynServer 2013 : Dependent Services and SQL - Office Web Apps Server
- Microsoft LynServer 2013 : Dependent Services and SQL - Network Dependencies (part 2) - Defining Network Sites
- Microsoft LynServer 2013 : Dependent Services and SQL - Network Dependencies (part 1) - Supporting Lync Phone Edition with DHCP
- SQL Server 2012 : Performance Monitor Overview (part 5) - Remotely Running PerfMon
- SQL Server 2012 : Performance Monitor Overview (part 4) - Working with Data Collector Sets
- SQL Server 2012 : Performance Monitor Overview (part 3) - Getting Started with PerfMon - Monitoring Real-Time Server Activity, Starting Out with Data Collector Sets
- SQL Server 2012 : Performance Monitor Overview (part 2) - New PerfMon Counters for SQL Server 2012
- SQL Server 2012 : Performance Monitor Overview (part 1) - Reliability and Performance Monitor
- SQL Server 2012 : Knowing Tempdb - Configuration Best Practices (part 2) - Tempdb Initial Sizing and Autogrowth , Configuring Multiple Tempdb Data Files
- SQL Server 2012 : Knowing Tempdb - Configuration Best Practices (part 1) - Tempdb File Placement