Sandboxing IIS

From: J. Random-User (jrandom_user@hotmail.com)
Date: 09/20/02


From: "J. Random-User" <jrandom_user@hotmail.com>
Date: Fri, 20 Sep 2002 11:56:31 -0700


I'd like to allow somebody who is NOT in the
Administrators group in Windows 2000 Server to be able to
create virtual directories under IIS. Is this possible?
Basically, I'm interested in giving web folks the access
they need to complete their web-related tasks without
giving them the ability to do anything else on a system
level. Any ideas? Everything I've read so far tells me
that access to the metabase is required to create virtual
directories and only accounts in the Administrators group
have access to it. Is this another Microsoft security faux-
paux or is there a supported or recommended way of
accomplishing this?