all groups > iis security > december 2003 >
You're in the

iis security

group:

Problems with new accounts accessing protected areas of site.


Problems with new accounts accessing protected areas of site. Cam M. Johnson
12/30/2003 3:56:10 PM
iis security: The Facts:
1. Windows 2000 Web Server
2. Windows 2003 Domain Controller
3. Web Server uses FrontPage server extensions
4. Have had the same problem with different web servers and domain controllers

The Sad Story:
We have a web site with two subwebs. One subweb uses basic authentication the other uses NT challenge and response. When we add a new user to the domain, make him an average domain user, and try and assign him as a browser to either subweb, he gets denied access. The process of adding the permissions, basically assigning him as a browser with the fun web based admin, goes through with out a hitch. No matter what kind of access we give the account, still no luck. We even have the same problem if we add the account locally to the web server.

We gave this a shot (http://support.microsoft.com/default.aspx?scid=kb;EN-US;152526) but no luck. Even restarting the server does not allow the user to access the restricted part of the site. In case your wondering, we know exactly what the password is and are adding the correct domain prefix.

In the past, some accounts would work and others would not, there was not really a pattern to follow.

Does anyone have any thoughts?

Respectfully
RE: Problems with new accounts accessing protected areas of site. Cam M. Johnson
12/30/2003 4:46:16 PM
Here is what appears to be the solution to the problem:

RE: Problems with new accounts accessing protected areas of site. yonlinemanghn NO[at]SPAM microsoft.com
1/2/2004 2:59:33 AM
Hello,
For Basic authentication to work, the users need the "Logon Locally"
privilege on the IIS server. For Integrated windows authentication to
work, the users need the "Access this computer from the network" privilege
on the IIS server. Make sure both the local and the effective settings
(controlled by the DC) are enabled.
Also, if you enable all types of security auditing, you will find messages
in your event logs indicating that the users do not have the required logon
type to the computer.
http://support.microsoft.com/default.aspx?scid=kb;en-us;185377
http://support.microsoft.com/default.aspx?scid=kb;en-us;264921

Thanks,
Yogita Manghnani
Microsoft Developer Support
Internet Information Server

*********************************************************************
[quoted text, click to view]
account name for newsgroup participation only.<<

This posting is provided "AS IS" with no warranties, and confers no rights.
You assume all risk for your use.

© 2003 Microsoft Corporation. All rights reserved.
*********************************************************************
AddThis Social Bookmark Button