Improve company productivity with a Business Account.Sign Up

x
?
Solved

Grant IIS server account network access

Posted on 2009-05-04
6
Medium Priority
?
368 Views
Last Modified: 2012-08-14
I have a server running IIS6 that we need to be able to access network resources on our network.  The server that it is on right now is not a domain controller.  Our domain controller does not have IIS installed on it.  How can I get the IUSR_SERVER1 account to be able to access other servers?
0
Comment
Question by:sharkbot221984
  • 3
  • 3
6 Comments
 
LVL 22

Expert Comment

by:cj_1969
ID: 24304564
Try granting the AD\<MachineName>$ account access to the resource and see if this grants it access.
Or try granting <MachineName>\IUSR_<MachineName> access.
0
 
LVL 8

Author Comment

by:sharkbot221984
ID: 24307586
The user that needs this went in and put his information DOMAIN\username in place of the IUSR_machinename and claims that is letting him do what he needs for now.  If this is true, I guess I could just create a domain account just for this purpose, but wouldn't that pose a security issue?
0
 
LVL 22

Expert Comment

by:cj_1969
ID: 24307737
yes ... it means that if anyone hacks the website they can execute code or access any resources that those credentials can.

That said ... this is also a legitimate way to deal with the problem.  It is a question of risk versus being able to do what you want to do.

A service account is definitely recommended over a user account as you are starting from scratch with permissions and you have some semblance of control over what it can access, there by limiting your risk and exposure if the site is compromised.  Same idea as changing the application pool logon ID to get code to do what you want.
0
What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

 
LVL 8

Author Comment

by:sharkbot221984
ID: 24308400
Okay that confirms what I was thinking, it's a catch 22.  I create a service account that makes it easy to have the websites gain access to resources needed that are stored on other servers, but that also creates a security issue.

I noticed in our AD, someone created a user account called IUSR_SERVER, but I've not seen this setup as the IUSR account on any other server.  Any thoughts as to why this is done?  Was/is this an attempt at a service account that's more secure than a general user account?
0
 
LVL 22

Accepted Solution

by:
cj_1969 earned 2000 total points
ID: 24308615
I t could be ... I don't think an IUSR_<> account is created in AD by anything as a default.  

I just found this page, take a look at it, it might have some other options that you can use ... http://imar.spaanjaars.com/QuickDocId.aspx?quickdoc=276

0
 
LVL 8

Author Closing Comment

by:sharkbot221984
ID: 31577821
I agree, I think the IUSR_<> account in AD wasn't made by default.  Looks like that link is a good guide for all the options.  I think the service acount in AD is the best choice, just give it access to only that which you need it to, and give it a very strong password.
0

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

606 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question