Re: Granting permissions to "NETWORK AUTHORITY"

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 05/28/05

  • Next message: Robert L [MS-MVP]: "Re: VPN between 2 2k3 servers"
    Date: Sat, 28 May 2005 03:07:14 GMT
    
    

    On 27 May 2005 04:50:36 -0700, "Brian Cline" <clib@gptruck.com> wrote:

    >The other morning I dcpromo'd our internal web server (Win2003 Server,
    >IIS6), and after I did this my IIS6 sites all began requiring
    >authentication since the anonymous account failed, giving me 401.1
    >errors. Two messages appear in my application event log:
    >
    >IISADMIN service failed to verify anonymous/wam account
    >DOMAIN\IUSR_SERVER. Some IIS functions can fail for this reason.
    >
    >Error: The Template Persistent Cache initialization failed for
    >Application Pool 'DefaultAppPool' because of the following error: Could
    >not create a Disk Cache Sub-directory for the Application Pool. The
    >data may have additional error codes..
    >
    >
    >I tried following the directions on
    >http://support.microsoft.com/d­efault.aspx?scid=kb;en-us;3320­97, but
    >when I try to grant permission to "NETWORK SERVICE", it tells me that
    >there is no such object.
    >
    >How can I grant those permissions in Q332097 to network service? Any
    >help is appreciated here.

    Try the IWAM and IUSR accounts instead. Normally these are local
    accounts. When you promote a server to a DC, there are no longer any
    local accounts. See:

    http://support.microsoft.com/default.aspx?scid=kb;en-us;275167
    http://support.microsoft.com/default.aspx?scid=kb;en-us;Q263140
    http://support.microsoft.com/default.aspx?scid=kb;en-us;300432
    http://support.microsoft.com/default.aspx?scid=kb;en-us;190005

    Jeff


  • Next message: Robert L [MS-MVP]: "Re: VPN between 2 2k3 servers"

    Relevant Pages

    • Re: Creating/editing user accounts
      ... Subject: Creating/editing user accounts ... always have the anonymous account run in the context of a specific user ... >manipulate accounts from the Web. ... >only ID with the rights to create and edit user accounts are sys-admins, ...
      (Focus-Microsoft)
    • Re: Password "security" - was"Passwords with Lan Manager (LM) under Windows" and
      ... using local accounts, one could easily boot to an alt OS and replace the SAM ... since the local admin owns the EFS ... > Regarding laptop security, you're in the same boat as the rest of us. ...
      (Pen-Test)
    • Re: Multiple Applications on TS
      ... Why on earth would you want to maintain local accounts, ... MCSE, CCEA, Microsoft MVP - Terminal Server ... > server,the group policy is not in effect.Is group policy meant ...
      (microsoft.public.windows.terminal_services)
    • Re: External Trust - Cant see share contents
      ... Use the universal groups to configure the share access permissions. ... Windows Server 2003 Domain with an External Trust to the remote ... are Share = Local group with local accounts have Change. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Default Domain Policy - Password Chg 90 days
      ... Mathieu CHATEAU ... There are certain accounts that have ... Or is it used for local accounts ... > user - it is NOT being done through local GPOs. ...
      (microsoft.public.windows.server.active_directory)