Groups | Blog | Home
all groups > iis security > september 2003 >

iis security : Group Policy effects on IIS 5


tzone
9/12/2003 9:29:00 AM
I'm having problems getting a Form (ASP script) to run on
our website. Getting this error message- "HTTP 500
Internal server error". Here is the catch if I use a
domain admin account in IIS for the anonymous web account
it works fine??? Also it didn't work with the default
Anonymous Web User account.

Running IIS 5 with URLSCAN 2.5 installed IIS lockdown. The
server is configured to allow ASP.

The Web anonymous login account isn't using the default
local user account. I created a user in active dir. and a
new global security group and removed the account from
the domain user group. I also added the new web user
account into the Web Anonymous Access group on the IIS
server. I have a few GPO's setup at the domain level which
our web server is a part of. I have created a GPO just for
the IIS computer allowing all authenticated users network
access. I also allow Local login for the new Anony. Web
user account and it's setup to run as a batch. Anybody
Roger Abell
9/12/2003 5:54:37 PM
Your problem has nothing to do with Group Policy,
at least not so unless you have used restricted groups
or software restriction policies the impact the webserver
or this domain account.

Make the domain account a member of the Users group
on the webserver. If the webserver is a domain controller
specifically grant the account the local logon right.

--
Roger Abell
Microsoft MVP (Windows, Security)
MCSE (W2k3,W2k,Nt4) MCDBA
[quoted text, click to view]

tzone
9/16/2003 8:57:03 AM
I have done this already and still it doesn't work. I have
even gone back to using the webservers local IIS user
account and still nothing.
[quoted text, click to view]
AddThis Social Bookmark Button