IUSR/IWAM security problem (re: KB297519)

From: Bettie Claxton (BettieClaxton_at_discussions.microsoft.com)
Date: 04/21/05


Date: Thu, 21 Apr 2005 10:34:03 -0700

I am getting the two errors shown in this KB article. Basically, DCOM is
unhappy because it cannot logon. The particular server (let's call it LB1)
running IIS 5 has a local policy that allows the local IUSR and IWAM accounts
to log on as a batch service but there is a domain controller policy that is
overriding it. I cannot remember why this was done but I do remember PSS
talking me through this as a way to solve some dire problem. I looked at our
other IIS server (LB2) and it it is configured the same way and also being
overridden by the domain security policy. LB2 is not having these errors,
but they are filling up LB1's event log. What do I need to do to make it
happy?

Thanks
Bettie

-- 
Bettie


Relevant Pages

  • Re: How to allow users to create groups and shares
    ... Add the user/group to the Computer configuration, windows settings, security settings, Local policies, "Allow logon locally" in the Default domain controllers policy and on a existing or new created policy for the member servers. ... Filtering: Not Applied ... check with GPMC on the server or from a client the policy settings. ...
    (microsoft.public.windows.server.active_directory)
  • Domain Controller Security Policy errors
    ... Security Policy or the Domain Controller Security Policy. ... The DC is also a print and file server. ... The domain controller for Group Policy operations is not available. ...
    (microsoft.public.win2000.active_directory)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • Re: Security Logon/Logoff Events
    ... I haven't yet set password policy or configured account lockout policy so I ... will do that in due course to fully secure the server. ...
    (microsoft.public.windows.server.sbs)
  • Re: Move W2K3 server to its own OU seperate from SBS (MyBusiness) OU
    ... OU and move the member server to so that it does not inherit it's GPO from ... policies from inheriting the default domain policies of the SBS ... section of the default domain policy. ... In direct answer to your question, you would need to filter this ...
    (microsoft.public.windows.server.sbs)