Solved

IIS 6 - Intranet, Protected Directories and access for certian network groups

Posted on 2007-03-26
7
339 Views
Last Modified: 2008-02-01
We have a local Intranet.  I have searched the forum and have not found the answer I am looking for.  We are using Windows 2003, IIS 6 and we have an Active Directory system.  Here is what I want to accomplish.

IT wants to have their own directory of documents that is secure so no other departments can have access.  I do not want IT users to be prompted for a userid and password.  I would like the system to know what Active Directory group they are apart of and allow access.  In IIS 6, I open the Intranet website and choose the folder ITS.  I right click and go to Permissions.  Now here is where I get stuck.  I have no idea what to edit.  It looks as if I can add the IT group but I am unsure and do not want to screw anything up.

I know I can use a database with a list of users and use ASP.NET to grab the user name, compare and allow access if needed but that means I have to keep that list updated.  I would like to utilize the IT group that is in the network system.

Thanks for the help
0
Comment
Question by:hcaadev
  • 3
  • 3
7 Comments
 
LVL 70

Expert Comment

by:Chris Dent
ID: 18795698

If you're using ASP.NET to handle your security and you happen to be using Integrated or Forms based authentication you should be able to pick up information such as Group Membership using System.DirectoryServices.

How are you currently handling authentication?

Chris
0
 

Author Comment

by:hcaadev
ID: 18795798
We don't really have any on the Intranet.  Anyone in our domain can access the Intranet.  We have a couple of applications that only specific users can access.  We have programmed the allowed users in the database the the program utilizes.  We grab the user id using asp.net and verify with the database to see if they are allowed.  This works great for these programs since there are a small number of users.

How would you code what you are talking about using System.DirectoryServices?  Again, what I am trying to do is to restrict non IT users from viewing a web page that is accessible from the Intranet.  If an IT user clicks on the IT link, the system will know they are from IT and allow access.  If the user is non-IT than no access will be granted.  I do not want to have to manage the users.  I would rather we use the group that the Active Directory Admin updates.

options?  
0
 
LVL 34

Expert Comment

by:Dave_Dietz
ID: 18798128
You could simply secure the contents on the file system by only allowing the 'IT Group' to have Read permissions and then set the directory to use Integrated Authentication in IIS.

If the user isn't part of that group they will be prompted for credentials but won't be able to get in.

Dave Dietz
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 70

Assisted Solution

by:Chris Dent
Chris Dent earned 250 total points
ID: 18798403

That would certainly be easier.

Developing something to authenticate them against AD isn't really trivial.

Chris
0
 

Author Comment

by:hcaadev
ID: 18800608
Can anyone walk me through the IIS Setup?  

- When I go into IIS and expand Websites, I see my website Intranet
- I highlight and right-click a folder (test)
- I go to permissions and see
   - Administrators
   - IIS_WPG
   - Internet Guest Account
   - System
   - USers

How can I make this directory accessible to only those who are in the IT Group?

thanks
0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 250 total points
ID: 18800671

Leave IIS_WPG, Administrators and System. Remove Internet Guest Account and Users. Add in a group that covers the members of IT.

Chris
0
 

Author Comment

by:hcaadev
ID: 18801154
Thanks Chris-Dent and Dave_Dietz!!  The solution worked.  I gave Chris the most points since he helped the most and gave Dave some points for his answer as well.  I hope you both agree.  Have a great day.
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
SSL Exchange server 2010 and IIS 11 63
IIS and .Net Web Service 24 111
ASP Classic - Load test 2 33
SBS2011 - CSR Certificate 4 50
First of all, clustering IIS is something you should rarely consider doing. In almost all cases, Microsoft Network Load Balancing (NLB) (http://technet.microsoft.com/en-us/library/cc758834(WS.10).aspx) is a much better solution when you need to p…
Prologue It is often required to host multiple websites on a single instance of IIS, mostly in development environments instead of on production servers. I am sure it is not much a preferred solution on production servers but this is at least a pos…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now