Re: Domain-based IUSR and IWAM accounts

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 06/29/05


Date: Tue, 28 Jun 2005 22:51:15 GMT

On Tue, 28 Jun 2005 09:09:09 -0700, "Steve"
<Steve@discussions.microsoft.com> wrote:

>We have multiple IIS servers throughout our domain. We are constantly
>running into the issue where the GPO overwrites the local account setting,
>which is default by design.
>
>MS Article 275167 states 3 resolutions.
>Option one is to run iisreset, which our OPS dept is tired of.
>
>Option two is not to run the GPO from the root, something our Engineering
>team doesn't like.
>
>Option three is to create domain based IWAM and IUSR accounts and setting
>permissions on each IIS server to the domain accounts.
>
>Are there any known issues with doing this?

Only the security issue tha the account is a domain account instead of
local, with more access. But that's what you want anyway, so it's a
moot point.

Jeff



Relevant Pages

  • Re: How to Setup TS User
    ... I'm not sure why you use a dummy account. ... user logs on with personal domain account to local workstation ... Yes all accounts are domain accounts, ... what is the correct process for them to logon ...
    (microsoft.public.windows.terminal_services)
  • Re: Accessing security information from an authentication provider
    ... doesn't seem to work for domain accounts, ... someone disabling or restricting the null account, ... the GetAuthDataForUser only works for machine local ... network shares and such without somehow authenticating to a domain ...
    (microsoft.public.platformsdk.security)
  • Re: Startup account password must be rekeyed after every windows u
    ... I use domain accounts on my servers with no issues... ... What about my group policy or local policy question? ... Steve ... I would expect the local system account to ...
    (microsoft.public.sqlserver.setup)
  • Re: Active Directory mode security and SPS 2003?
    ... You can install SharePoint in Active Directory Account Creation Mode. ... if you do this then you can not use any existing domain accounts. ... > the use of Active Directory mode for security. ...
    (microsoft.public.sharepoint.portalserver)
  • RE: account lockout problems
    ... This occurs only with the domain accounts. ... > The account policy is set to lock the account after 3 logins. ... > Is your problem only with domain accounts or with local accounts as ... >> Do You Yahoo!? ...
    (Focus-Microsoft)