ARCHIVED: In IIS, how do I set up password protection for a web site?
There are two steps in setting up password protection for your Internet Information Services (IIS) web site. First, you must disable anonymous access to the web site. Then you must specify which users are allowed to view the web pages. The Windows NT, 2000, and XP operating systems include the NTFS file system, which allows you to specify exactly which user accounts have access to folders and files on your hard drive.
To disable anonymous access to your web site:
- Start the Internet Service Manager and right-click .
- Click , and in the "Connect to Computer" field, type the name of the computer running IIS.
- Click , and in the left side of the window, click the name of your server.
- Right-click the name of your web site and click .
- Select the tab, and under "Anonymous Access and Authentication Control", click the button.
- Uncheck the box next to .
- To enable web browsers other than Microsoft Internet Explorer, check the box next to .
- Click twice.
You may need to stop and restart your web site, or reboot the computer, for the change to take effect.
At Indiana University, you can restrict access to files, and therefore web sites, based on ADS domain user accounts. To do so:
- Through My Computer or Windows Explorer, find the directory that contains the web site to which you want to restrict access.
- Right-click the folder, select , and then click the tab.
- Add and remove names until only the appropriate people are listed as having access. Click .
Your web site will now require authentication based on the information you just specified.
For more information about protecting your IIS server, see the University Information Security Office's Protecting IIS page.
This is document ajqq in the Knowledge Base.
Last modified on 2021-09-07 17:16:31.