Knowledge Base

How to troubleshoot permissions in Internet Information Server 4.0

Article ID: 185874

Article Last Modified on 1/12/2007


APPLIES TO


This article was previously published under Q185874
We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 6.0 running on Microsoft Windows Server 2003. IIS 6.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site:

IN THIS TASK

SUMMARY

This step-by-step article discusses some of the best practices for troubleshooting in the area of access to resources, which can become a complex task when you try to secure Web servers.

Site administrators frequently work blind when they try to troubleshoot access problems. Monitoring how the server is being used is a good place to start.

back to the top

Monitor server use

To monitor server use, an administrator can set up auditing and logging:

back to the top

Audit user logons

  1. Click Start, point to Programs, and then click Administrative Tools (Common) to open User Manager for Domains.
  2. Select the appropriate domain for the IIS server. To do this, click Select Domain on the User menu.
  3. On the Policies menu, click Audit.
  4. Click to select Audit These Events.
  5. For both Logon and Logoff, click to select both the Success and the Failure check boxes.
  6. Click OK.
back to the top

Enable auditing on objects

  1. Click Start, point to Programs, and then click Administrative Tools (Common) to open User Manager for Domains.
  2. On the Policies menu, select Audit.
  3. Click to select Audit These Events.
  4. For both File and Object Access, click to select both the Success and the Failure check boxes.
  5. Click OK.
back to the top

Select objects to audit

  1. Click Start, point to Programs, and then click Windows NT Explorer to start Windows NT Explorer.
  2. Select the file or folder that you want to audit.
  3. Right-click the file or folder, and then click Properties.
  4. Click the Security tab.
  5. Click Auditing.
  6. Click Add.
  7. Select the appropriate domain for the IIS server from the drop-down menu.
  8. Select Everyone, click Add, and then click OK.
  9. Click to select the Success and the Failure check boxes for all of the following:
    • Read
    • Write
    • Execute
  10. Click OK.
back to the top

Enable W3C extended logging

  1. Start the Internet Service Manager (ISM). To do this, click Start, point to Programs, click Windows NT 4.0 Option Pack, click Microsoft Internet Information Server, and then click Internet Service Manager.
  2. Under Internet Information Server, select the IIS server.
  3. Right-click the Web site, and then click Properties.
  4. On the Web Site tab, click to select the Enable Logging check box. By default, Enable Logging is selected.
  5. Click Properties.
  6. Click the Extended Properties tab.
  7. Click to select at least the following check boxes:
    • Date
    • Time
    • Client IP Address
    • User Name
    • Method
    • HTTP Status
    • Win32 Status
  8. Click OK to exit the logging properties.
  9. Click OK to exit the Web site properties.
Basic auditing and logging is now in place.

back to the top

Stop and restart the Web service

After you enable basic auditing and logging, you must stop and then restart the Web service to clear any cached logon information. To do this, do one of the following: back to the top

Clear the security log

  1. Open the Event Viewer. To do this, click Start, point to Programs, click Administrative Tools (Common), and then click Event Viewer.
  2. On the Log menu, click Security to select the security log.
  3. On the Log menu, select Clear All Events.NOTE: Microsoft recommends that you save the existing security log. To do this, click Yes, and then specify a folder or file to save to.

  4. Click Yes to clear the security log.
back to the top

Troubleshoot the Web server

After you have examined the server, try to access the resource from a browser. If you refresh the security log in the event viewer, a series of audited events is listed. Examine the security log entries and ask these questions:
  1. Are any access-denied errors present in the audit log? (You may see some error messages that are related to object access and protected storage; you can safely ignore these messages.)
  2. What account is being logged on? Is it what you expected?
  3. Does this account have access to the file in question? You can check this by looking at the file access entries in the audit log.
  4. What about the W3C log? Are there any HTTP-401 or HTTP-403 errors? Why are they there?
Use the File Monitor (Filemon.exe) tool and the Registry Monitor (Regmon.exe) tool to view real-time system activity. File Monitor enables you to view and to capture real-time file system activity. Registry Monitor enables you to view and to capture real-time system registry activity.

For more information about how to use File Monitor, visit the following Web site:For more information about how to use Registry Monitor, visit the following Web site: back to the top

Tips

The following are some rules and tips about permissions and IIS 4.0: back to the top

Troubleshooting resources

To troubleshoot complex issues, you can use the following resources: back to the top

Tools to use

The site http://www.microsoft.com/technet/sysinternals/default.mspx has many utilities that are helpful when troubleshooting Windows NT issues in addition to the File Monitor and Registry Monitor tools that are discussed in the "Troubleshoot the Web server" section. back to the top

REFERENCES

For more information about security, visit the following Microsoft Web site: For more information about permissions for IIS 4.0, click the following article numbers to view the articles in the Microsoft Knowledge Base:

187506 Required NTFS permissions and user rights for IIS 4.0

280383 IIS security recommendations when you use a UNC share and username and password credentials

240735 How to reset multiple virtual server permissions in FrontPage 2000

For more information, click the following article number to view the article in the Microsoft Knowledge Base:

271071 How to set required NTFS permissions and user rights for an IIS 5.0 Web server

For more information, click the following article number to view the article in the Microsoft Knowledge Base:

321892 Default settings in DCOMCNFG for IIS 5.0

For more information, click the following article number to view the article in the Microsoft Knowledge Base:

321893 Default settings in DCOMCNFG for IIS 4.0

For more information, click the following article number to view the article in the Microsoft Knowledge Base:

812614 Default permissions and user rights for IIS 6.0

The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, regarding the performance or reliability of these products. back to the top

Keywords: kbhowtomaster KB185874