IIS 6 - Intranet, Protected Directories and access for certian network groups

Posted on 2007-03-26
Last Modified: 2008-02-01
We have a local Intranet.  I have searched the forum and have not found the answer I am looking for.  We are using Windows 2003, IIS 6 and we have an Active Directory system.  Here is what I want to accomplish.

IT wants to have their own directory of documents that is secure so no other departments can have access.  I do not want IT users to be prompted for a userid and password.  I would like the system to know what Active Directory group they are apart of and allow access.  In IIS 6, I open the Intranet website and choose the folder ITS.  I right click and go to Permissions.  Now here is where I get stuck.  I have no idea what to edit.  It looks as if I can add the IT group but I am unsure and do not want to screw anything up.

I know I can use a database with a list of users and use ASP.NET to grab the user name, compare and allow access if needed but that means I have to keep that list updated.  I would like to utilize the IT group that is in the network system.

Thanks for the help
Question by:hcaadev
  • 3
  • 3
LVL 70

Expert Comment

by:Chris Dent
ID: 18795698

If you're using ASP.NET to handle your security and you happen to be using Integrated or Forms based authentication you should be able to pick up information such as Group Membership using System.DirectoryServices.

How are you currently handling authentication?


Author Comment

ID: 18795798
We don't really have any on the Intranet.  Anyone in our domain can access the Intranet.  We have a couple of applications that only specific users can access.  We have programmed the allowed users in the database the the program utilizes.  We grab the user id using and verify with the database to see if they are allowed.  This works great for these programs since there are a small number of users.

How would you code what you are talking about using System.DirectoryServices?  Again, what I am trying to do is to restrict non IT users from viewing a web page that is accessible from the Intranet.  If an IT user clicks on the IT link, the system will know they are from IT and allow access.  If the user is non-IT than no access will be granted.  I do not want to have to manage the users.  I would rather we use the group that the Active Directory Admin updates.

LVL 34

Expert Comment

ID: 18798128
You could simply secure the contents on the file system by only allowing the 'IT Group' to have Read permissions and then set the directory to use Integrated Authentication in IIS.

If the user isn't part of that group they will be prompted for credentials but won't be able to get in.

Dave Dietz
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

LVL 70

Assisted Solution

by:Chris Dent
Chris Dent earned 250 total points
ID: 18798403

That would certainly be easier.

Developing something to authenticate them against AD isn't really trivial.


Author Comment

ID: 18800608
Can anyone walk me through the IIS Setup?  

- When I go into IIS and expand Websites, I see my website Intranet
- I highlight and right-click a folder (test)
- I go to permissions and see
   - Administrators
   - IIS_WPG
   - Internet Guest Account
   - System
   - USers

How can I make this directory accessible to only those who are in the IT Group?

LVL 70

Accepted Solution

Chris Dent earned 250 total points
ID: 18800671

Leave IIS_WPG, Administrators and System. Remove Internet Guest Account and Users. Add in a group that covers the members of IT.


Author Comment

ID: 18801154
Thanks Chris-Dent and Dave_Dietz!!  The solution worked.  I gave Chris the most points since he helped the most and gave Dave some points for his answer as well.  I hope you both agree.  Have a great day.

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Today I came across an interesting issue that had me pulling my hair out.  I was troubleshooting a new internal web site which uses integrated security instead of anonymous.  When browsing the site from my laptop, I was able to access it with no iss…
What is an ISAPI filter?   •      It's an assembly (.dll file) that can add or change the way IIS works.   •      They can be enabled globally for your web server or on a site-by-site basis.   When the IIS server receives a request, enabling the ISAPI fi…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
In this video I am going to show you how to back up and restore Office 365 mailboxes using CodeTwo Backup for Office 365. Learn more about the tool used in this video here: (…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now