Technical instruction - IIS security
Review Microsoft’s latest policies and recommendations for Windows Servers, IIS, Azure and ohter components and infrastructure used for an installation.
Service account
It is recommended to use a service account for IIS instead of LocalSystem.
IIS settings
Security IIS Settings Checklist
Implement the IIS security settings
Technical instruction - IIS security settings | Prevent directory traversal
Technical instruction - IIS security settings | Set IIS URL filtering
Technical instruction - IIS security settings | IIS error pages not to display error information
Technical instruction - IIS security settings | IIS error pages not to display error information
Implment the HTTP response header
Enforcing the HTTPS in IIS
Configure Application Pool Identity
Disable Directory Browsing
Set NTFS Permissions
Other security aspects to consider
Technical instruction - Installing application on Windows Server | Security