Groups | Blog | Home
all groups > iis security > september 2005 >

iis security : Active Directory and IIS-6


Thomas McFarlane
9/28/2005 5:23:26 AM
Is it best practice to join an IIS-6 (run on Windows 2003 server) to a
Windows 2003 Active Directory Domain ? Do you have any references/articles
about this subject ?

TIA

Thomas

Thomas McFarlane
9/28/2005 8:18:09 AM
Thanks Leon for quick response. My application server (IIS-6) is for
Internet only. Not intranet. You are right, for internal usage, it does make
sense to make IIS member of AD. But my AD ADmin. insists to make all
application servers (IIS & SQL) as members of AD.

Thomas

[quoted text, click to view]

Leon Mayne [MVP]
9/28/2005 12:38:35 PM
[quoted text, click to view]

Not sure of any articles, but in general I would say yes, because:
1) You can manage the policies and patches for the server centrally
2) You get the domain security model implemented (e.g. users can use their
domain accounts to log on to your web applications)
3) You can use Kerberos authentication for web apps, if required

It depends on the situation. I guess there are circumstances when you would
want the server to be completely standalone, but if it's going to be a
webserver for your internal organisation apps then I don't see why you
wouldn't want to put it in the domain.

jeff.nospam NO[at]SPAM zina.com
9/28/2005 4:01:03 PM
On Wed, 28 Sep 2005 05:23:26 -0400, "Thomas McFarlane"
[quoted text, click to view]

Since it's an intranet, joining the domain makes sense. Then you can
manage them with AD policies, use AD accounts for access and so on.
But it's not critically necessary, and depends a lot on your company's
policies and strategy, as well as network topology.

AddThis Social Bookmark Button