/
Technical instruction - IIS security

Technical instruction - IIS security

Review Microsoft’s latest policies and recommendations for Windows Servers, IIS, Azure and ohter components and infrastructure used for an installation.

Service account

It is recommended to use a service account for IIS instead of LocalSystem.

IIS settings

Security IIS Settings Checklist

  1. Implement the IIS security settings

    1. Technical instruction - IIS security settings | Prevent directory traversal

    2. Technical instruction - IIS security settings | Set IIS URL filtering

    3. Technical instruction - IIS security settings | IIS error pages not to display error information

    4. Technical instruction - IIS security settings | IIS error pages not to display error information

  2. Implment the HTTP response header

    1. https://signifikant.atlassian.net/wiki/x/AQD2qg

  3. Enforcing the HTTPS in IIS

    1. https://signifikant.atlassian.net/wiki/x/BADe0g

  4. Configure Application Pool Identity

    1. https://signifikant.atlassian.net/wiki/x/BQDa0g

  5. Disable Directory Browsing

  6. Set NTFS Permissions

    1. https://signifikant.atlassian.net/wiki/x/KwDe0g

Other security aspects to consider

Technical instruction - Installing application on Windows Server | Security

Related content

Technical instruction - Configure Application Pool Identity
Technical instruction - Configure Application Pool Identity
More like this
Technical instruction - IIS security settings
Technical instruction - IIS security settings
More like this
Technical instruction - Add http response header on IIS
Technical instruction - Add http response header on IIS
Read with this
Technical instruction - Set NTFS Permissions
Technical instruction - Set NTFS Permissions
Read with this
Technical instruction - Enforce HTTPS in IIS
Technical instruction - Enforce HTTPS in IIS
Read with this