Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


September 2001

Authentication Problems After Migration

RSS
Subscribe to Windows Web Solutions | See More Migration Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

I recently migrated Web sites from several IIS servers to one server to consolidate administration. Since then, I've had problems with authentication. For example, one site works fine if you log on as a user, but when you access the site anonymously, you receive error 401 Access denied. The Web site permits Read access and Anonymous access, and no IP address restrictions are in place. I reviewed NTFS permissions on the site, which allow Everyone Read or Everyone Change. How can I identify the problem?

Such authentication problems are common and can be confounding. If the IUSR_servername user account (or whatever account you use for Anonymous authentication) has the Log on Locally user right, the problem is with NTFS permissions. The frequency of such problems underscores the complexity of setting NTFS permissions on a Web server correctly.

First, check the content in the Web root (the Web site's home folder) and all subfolders. Apparently, you've done so. Although I don't recommend using the Everyone account often, this account clearly isn't causing your problem.

Second, inspect permissions for all virtual directories. This inspection often reveals permissions-related problems because content for a virtual directory can be anywhere on the server or even on another server.

Third, and this process can be trickier still, verify that all files any Web applications call, including executables and scripts, have sufficient permissions. Remember to include files called from scripts (e.g., Active Server Pages—ASP—files).

If this process sounds like a lot of work, it is. You're in luck, however, because an excellent tool can reduce this task to minutes. File Monitor (Filemon) is free from http://www.sysinternals.com. Filemon opens a window that displays not only each file access that the system performs but also the kind of access and its success or failure. Figure 1 shows a Filemon display. When I have a permissions error that looks challenging, I can often short-circuit the entire troubleshooting process by launching Filemon, starting event capturing, then attempting the access that has been denied from a remote system. I then stop the event log and review the displayed results, looking for information about failed access. You can quickly spot problems with nested Include files, databases, invoked executables, content in virtual directories, and other problems that can remain hidden if you simply browse the file listing. Filemon is, to put it mildly, indispensable.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...


IIS and Web Administration Whitepapers Best Practices for SharePoint Backup & Recovery

Meeting Compliance Objectives in SharePoint

Improve SharePoint Performance for Remote Workers

Related Events Check out our list of Free Email Newsletters!

IIS and Web Administration eBooks Web Filtering: An Assessment

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Related IIS and Web Administration Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement