CertCities.com -- The Ultimate Site for Certified IT Professionals
Post Your Mind in the CertCities.com Forums Share share | bookmark | e-mail
  Microsoft®
  Cisco®
  Security
  Oracle®
  A+/Network+"
  Linux/Unix
  More Certs
  Newsletters
  Salary Surveys
  Forums
  News
  Exam Reviews
  Tips
  Columns
  Features
  PopQuiz
  RSS Feeds
  Press Releases
  Contributors
  About Us
  Search
 

Advanced Search
  Free Newsletter
  Sign-up for the #1 Weekly IT
Certification News
and Advice.
Subscribe to CertCities.com Free Weekly E-mail Newsletter
CertCities.com

See What's New on
Redmondmag.com!

Cover Story: IE8: Behind the 8 Ball

Tech-Ed: Let's (Third) Party!

A Secure Leap into the Cloud

Windows Mobile's New Moves

SQL Speed Secrets


CertCities.com
Let us know what you
think! E-mail us at:



 
 
...Home ... Editorial ... Columns ..Column Story Saturday: April 5, 2014


 Tip o'the Week  
Zubair Alexander
Zubair Alexander


 IIS 6 vs. IIS 7 IUSR Accounts
What happened to the IUSR_MachineName and IIS_WPG group in Internet Information Services (IIS) 7?
by Zubair Alexander  
11/12/2009 -- Microsoft has made several changes to the IIS account in IIS 7 on Windows Server 2008. In IIS 6, there was an IUSR_MachineName account and an IIS_WPG group on Windows Server 2003. These were local to the computer where IIS was installed. Microsoft used IUSR_MachineName account in the metabase.xml file so if you copied the metabase from one computer to another in IIS 6, it didn't work because the Security Identifier (SID) was a local SID attached to that machine. For this reason, you couldn't copy Access Control Lists (ACLs) using "xcopy /o" from one computer to another.

The IUSR_WPG group, which was used for application pool identities in IIS 6, had similar issues with the permissions. As a workaround, most administrators used an Active Directory domain account but businesses who had not deployed Active Directory did not want to add Active Directory just for this reason alone.

In IIS 7, Microsoft decided to use a different method. Now the IUSR_MachineName and IUSR_WPG group have been replaced by IUSR account and IIS_IUSRS group respectively. The new IUSR account and IIS_IUSRS group in IIS 7 are no longer tied to a specific machine in Windows Server 2008. In IIS 6, the IUSR_MachineName account was used for anonymous authentication both by HTTP and FTP service. In IIS 7, the IUSR account is used for anonymous authentication by HTTP and, unlike IIS 6, no longer requires a password.

However, don't get confused if you still happen to see an IUSR_MachineName account. This account will only appear when you install FTP server. Without the FTP server, you will not see this account.

The good news is that in Windows Server 2008 you can use "xcopy /o" to copy ACLs from one computer to another and you no longer need to worry about password expiration for the IUSR account.

If you look at the Authentication option in IIS 7, you'll notice that when Anonymous Authentication is enabled, by default it uses the IUSR account. You can verify this by going to the Web site and double-clicking Authentication in the IIS section in the Features view. For application pool identity, the NetworkService account is used by default. You can verify this by going to the Application Pools and in the Features view look under the Identity column for the identity that is used by the application pool. For example, both the DefaultAppPool and the OfficeServerApplicationPool use NetworkService as the identity in IIS 7.


Zubair Alexander, MCSE, MCT, MCSA and Microsoft MVP is the founder of SeattlePro Enterprises, an IT training and consulting business. His experience covers a wide range of spectrum: trainer, consultant, systems administrator, security architect, network engineer, author, technical editor, college instructor and public speaker. Zubair holds more than 25 technical certifications and Bachelor of Science degrees in Aeronautics & Astronautics Engineering, Mathematics and Computer Information Systems. His Web site, www.techgalaxy.net, is dedicated to technical resources for IT professionals. Zubair may be reached at .

 


More articles by Zubair Alexander:

-- advertisement --


There are 39 CertCities.com user Comments for “IIS 6 vs. IIS 7 IUSR Accounts”
Page 1 of 4
6/30/13: louis vuitton outlet from [email protected] says: nice articles louis vuitton outlet http://www.louisvuittonttoutlet.com
7/1/13: michael kors outlet store from [email protected] says: good share. michael kors outlet store http://www.michaelkorsioutlet.org/
7/4/13: christianlouboutinoutleta.com from [email protected] says: ths christianlouboutinoutleta.com http://www.christianlouboutinoutleta.com
7/5/13: gucci outlet online from [email protected] says: good share. gucci outlet online http://www.guccioutletstore-online.com
7/16/13: replica breitling from [email protected] says: More please, this information helped me consider a few more things, keep up the good work. replica breitling http://www.mmwatches2u.co.uk/
7/23/13: Oakley For Sale from [email protected] says: sunglass grabs zero cost supercharge... from a social project business!! Oakley For Sale http://www.fake-oakleysus.com
7/25/13: Cheap Mac Makeup from [email protected] says: Among the most fun you could get with out skipping makeup Cheap Mac Makeup http://www.cosmetics-wholesalerusa.com
7/26/13: Discount Louboutin from [email protected] says: good articles Discount Louboutin http://www.discount-louboutin.net/
7/26/13: viviennewestwoodshoe from [email protected] says: Information about how shoes Made Me Rich And Famous vivienne westwood shoes http://www.viviennewestwoodcheapest.co.uk
7/27/13: ReplicaOakleySunglas from [email protected] says: Here's Some Of The Technique That's In fact Enabling sunglass-experts To Advance Replica Oakley Sunglasses http://www.replicaoakleysglasses.com
First Page   Next Page   Last Page
Your comment about: “IIS 6 vs. IIS 7 IUSR Accounts”
Name: (optional)
Location: (optional)
E-mail Address: (optional)
Comment:
   

-- advertisement (story continued below) --

top