Re: 401.1 After IIS6 Setup

From: Bernard (qbernard_at_hotmail.com.discuss)
Date: 03/25/05


Date: Fri, 25 Mar 2005 09:48:45 +0800

Yes, in this cause, the user has no right to logon to the machine. check if
there's any local or domain policy which remove the user rights. You need
access from network, etc, refer this kb.
Default permissions and user rights for IIS 6.0
http://support.microsoft.com/?id=812614

-- 
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/
"WebGuyBob" <WebGuyBob@discussions.microsoft.com> wrote in message 
news:0A10BF70-0A78-427B-A1B3-D1664D83BEB4@microsoft.com...
> Hi, Bernard.
>
> Thanks for responding in this and the asp.net site's forum.  For the sake 
> of
> the users of this forum, I'll try to keep the thread alive here also.
>
> I appreciate the input. I followed your instructions explicitly, but I'm
> still getting the 401.1 error. Below my sig is the error in the Security
> Event Log. Am I to the point where I should delete the IIS site or at 
> least
> the docroot folder and start over, reselecting the appropriate users and
> perms? Is IWAM a factor here?
>
> I'm really wondering if there might be something about the security policy
> happening here. The reason I say that is because of the "Reason" indicated 
> in
> the error event:
>
> "The user has not been granted the requested logon type at this machine"
>
> Note: "logon type". Is that a clue?
>
> TIA,
>
> Bob
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Logon/Logoff
> Event ID: 534
> Date: 3/24/2005
> Time: 8:18:05 PM
> User: NT AUTHORITY\SYSTEM
> Computer: USPLSWEBH104
> Description:
> Logon Failure:
> Reason: The user has not been granted the requested
> logon type at this machine
> User Name: IUSR_USPLSWEBH104
> Domain: USPLSWEBH104
> Logon Type: 8
> Logon Process: Advapi
> Authentication Package: Negotiate
> Workstation Name: USPLSWEBH104
> Caller User Name: NETWORK SERVICE
> Caller Domain: NT AUTHORITY
> Caller Logon ID: (0x0,0x3E4)
> Caller Process ID: 1596
> Transited Services: -
> Source Network Address: -
> Source Port: -
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> "Bernard" wrote:
>
>> For Local SAM - open computer management, local users and groups, find 
>> the
>> IUSR_COMPUTER name account, right mouse on the account, and reset the
>> password.
>>
>> Then go to IIS MMC, open the site property, directory security tab,
>> anonymous access, reselect the iusr account, enter the password, click ok 
>> to
>> save.
>>
>> then go to command prompt, enter 'iisreset.exe' to restart IIS services.
>>
>> then test browse your site.
>>
>> -- 
>> Regards,
>> Bernard Cheah
>> http://www.tryiis.com/
>> http://support.microsoft.com/
>> http://www.msmvps.com/bernard/
>>
>>
>> "WebGuyBob" <WebGuyBob@discussions.microsoft.com> wrote in message
>> news:867C2E9C-1425-4975-AE5B-B62161B72D69@microsoft.com...
>> > Hello, folks.
>> >
>> > I have setup literally dozens of IIS6 Web sites and just ran into 
>> > subject
>> > problem.  I read the following from Mr. Wang in a German IT forum:
>> >
>> > "401.1 means that the username/password that you gave to IIS for
>> > authentication was incorrect. If this happens when you have Anonymous
>> > access
>> > enabled, it means that the username/password you configured in IIS for 
>> > the
>> > anonymous user is NOT the same as the NT user in the local SAM. Please
>> > synchronize them and try again."
>> >
>> > Being fairly new systems administration, my question is...How do I
>> > synchronize these accounts?
>> >
>> > TIA,
>> >
>> > Bob
>>
>>
>> 


Relevant Pages

  • Re: Problem
    ... Is the account logged into more than one machine or is it running a service ... What is the possible reason? ... Logon Type: 2 ... Logon Process: User32 ...
    (microsoft.public.windows.server.active_directory)
  • Re: Account lockout
    ... Logon type 4 is for batch jobs. ... it fails as the account is locked. ...
    (microsoft.public.security)
  • Re: Problem
    ... It attaches to EventLogs ... with the account you log onto the XP machine. ... 539 - Account is locked out, logon failed ... Logon Type: 2 ...
    (microsoft.public.windows.server.active_directory)
  • Trend, IIS, Permissions, Exhaustion and close to very bad language :-) Heelp!
    ... passwords using IIS and adsutil as in List 2. ... The errors in list 1 disappear and Trend Clients update as expected. ... Logon Failure: ... To reset the password for the IUSR_ComputerName account, ...
    (microsoft.public.windows.server.sbs)
  • Re: How do I trace a batch process?
    ... IIS installed on machine named EMPIRE but that its ... IWam_EMPIRE account is not granted the batch logon ...
    (microsoft.public.win2000.security)