<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx</link><description>Important note: This is not supported by Microsoft, do this at your own risk. Tool: Metabase Explorer from IIS 6.0 Resource Kit Step 1: User Account Management a) Create special user group for non local admin users. E.g. WebOperator b) Place the desire</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#115411</link><pubDate>Thu, 07 Sep 2006 02:47:07 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:115411</guid><dc:creator>qbernard</dc:creator><description>&lt;p&gt;That could be it with new changes in SP1, like component services security enhancement,etc. I have seen many users claimed that this workaround can't be applied to w2k3 sp1.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=115411" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#115369</link><pubDate>Wed, 06 Sep 2006 23:31:47 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:115369</guid><dc:creator>aimperial</dc:creator><description>Need to know if someone make it work over 2003 with SP1 ,cause all i got is acces denied i have review a lot of time the permission and simple doesnt work
tanx&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=115369" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#109457</link><pubDate>Fri, 25 Aug 2006 07:49:18 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:109457</guid><dc:creator>qbernard</dc:creator><description>Hi William, &lt;br&gt;Glad to know you are developing the utility. While I don't know the exact API, but generally you can use the WMI, ADSI interfaces to manage IIS. Some example here&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/technet/scriptcenter/scripts/iis/iis6/default.mspx"&gt;http://www.microsoft.com/technet/scriptcenter/scripts/iis/iis6/default.mspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;for .net you can use system.directoryservices&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/iissdk/html/cd63ff7d-f84b-4a1a-8c87-2a72fcf33402.asp"&gt;http://msdn.microsoft.com/library/default.asp?url=/library/en-us/iissdk/html/cd63ff7d-f84b-4a1a-8c87-2a72fcf33402.asp&lt;/a&gt;&lt;br&gt;&lt;br&gt;bare in mind that no matter what interface you use, the account need to have permissions on the metabase.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=109457" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#109422</link><pubDate>Fri, 25 Aug 2006 05:32:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:109422</guid><dc:creator>williambeyond</dc:creator><description>hm... then I will have to create a utility similar to IIS Manager but allows non-server-admin users to be able to administrate IIS,&lt;br&gt;&lt;br&gt;is there any reference/example/.NET API I can follow?&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=109422" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#108834</link><pubDate>Wed, 23 Aug 2006 02:29:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:108834</guid><dc:creator>qbernard</dc:creator><description>SP1 or even R2 has new security restriction. I have no time to test it yet. So it could due to the new restriction that this workaround is not working.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=108834" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#108832</link><pubDate>Wed, 23 Aug 2006 02:22:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:108832</guid><dc:creator>williambeyond</dc:creator><description>I have the same problem too! My server WinServer2003 R2 have SP1 on,&lt;br&gt;I have gave Full control to every node, but when I try to connect to the server remotely via IIS Manager, it just fail with &amp;quot;You have been denied access to this machine&amp;quot;&lt;br&gt;&lt;br&gt;I have it working before without SP1 on a window2003 NT server.&lt;br&gt;&lt;br&gt;any help?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=108832" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#106424</link><pubDate>Tue, 01 Aug 2006 16:52:37 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:106424</guid><dc:creator>Dimitri</dc:creator><description>Please test this with SP1, it doesn't work properly.&lt;br&gt;You have to give Full Control to the LM level to see websites, then you see the websites. Still, if you have Full Control on a certain website, you can for example create a virtual directory, but you can never delete it. Also when you request the properties you get an &amp;quot;Access Denied&amp;quot; popup, but you can still see and change properties after that. Anyone know how to get this working properly ?&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=106424" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#101735</link><pubDate>Sat, 17 Jun 2006 04:49:21 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:101735</guid><dc:creator>qbernard</dc:creator><description>Mm.. sp1. interesting. I have not tested it with SP1 yet. You might want to get filemon / regmon from sysinternals.com to trace the access denied.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=101735" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#101701</link><pubDate>Fri, 16 Jun 2006 20:02:59 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:101701</guid><dc:creator>MAXIMEP</dc:creator><description>Hello &lt;br&gt;I have the same problem.&lt;br&gt;Hall was correctly configured, AND WORKS, until I install SP1 on the server.&lt;br&gt;Now I have Acces Denied when I connect remotely, But works fine localy.&lt;br&gt;&lt;br&gt;Any Ideas ???&lt;br&gt;&lt;br&gt;Thanks&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=101701" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#80748</link><pubDate>Wed, 11 Jan 2006 09:35:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80748</guid><dc:creator>qbernard</dc:creator><description>Hi Dave, &lt;br&gt;It sounds like permissions issue. if you can managed IIS as and administrator but you can't with the custom user - meaning he/she doesn't has required priviliges to manage IIS. So I would suggest you verify you configuration again.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80748" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#80659</link><pubDate>Mon, 09 Jan 2006 19:40:27 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80659</guid><dc:creator>Dave</dc:creator><description>I believe that I have the permssions correct in Metabase Explorer.  However once in the MMC Snap-in the Web Sites fail to come up unless I am an administrator.  Any thoughts?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80659" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#80259</link><pubDate>Wed, 04 Jan 2006 04:47:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80259</guid><dc:creator>bernard</dc:creator><description>Great! but i'm still curious on why can't you grant READ at the first place ? I mean at the w3svc node and granting full control at LM node could introduce hidden risks, and if you forgot to further lock down the sub nodes, the user will be able to manipulate all the metabase keys under the node.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80259" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#80231</link><pubDate>Tue, 03 Jan 2006 20:32:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:80231</guid><dc:creator>Rob</dc:creator><description>Bernard,&lt;br&gt;&lt;br&gt;In my case, I had to grant Full on the LM node in order for the user to see the Web Sites.  Once that was done, all other permissions could be set as Read, or as otherwise desired.&lt;br&gt;&lt;br&gt;Thanks!&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=80231" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#79912</link><pubDate>Thu, 29 Dec 2005 01:59:45 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:79912</guid><dc:creator>bernard</dc:creator><description>Hi Rob,&lt;br&gt;&lt;br&gt;Did the user has READ permission on the W3SVC node? step 2e ??&lt;br&gt;Since you are able to sort out app pool and web service extensions node, this looks like just a permission issue on w3svc node.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=79912" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#79887</link><pubDate>Wed, 28 Dec 2005 17:25:15 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:79887</guid><dc:creator>Rob</dc:creator><description>Attempting to implement your workaround to allow a non local box admin to administer IIS 6.&lt;br&gt;&lt;br&gt;All appears to work except step 3.   When a user who is a member of the appropriate group logs in the the server, and runs the custom IIS admin, they can see the app pools, and web service extensions, but nothing is visible in web sites.&lt;br&gt;&lt;br&gt;I have verified via Metabase Explorer that the group they are in has Full Control to the individual sites under W3SVC and that the permission is present at all sub keys.&lt;br&gt;&lt;br&gt;On your suggestion I tried again with Regmon and Filemon running in the background.  Absolutely nothing in Filemon, and no &amp;quot;Access Denied&amp;quot; in Regmon, though several &amp;quot;Not Found.&amp;quot;&lt;br&gt;&lt;br&gt;I welcome any additional insight.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=79887" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#76231</link><pubDate>Wed, 23 Nov 2005 05:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:76231</guid><dc:creator>bernard</dc:creator><description>Actually, you can add local groups to the IIS_WPG group.  For some reason it will not let you add local groups to local groups in the GUI.  If you go to the command prompt and type &lt;br&gt;'net localgroup &amp;quot;IIS_WPG&amp;quot; &amp;quot;TheLocalgrouptoAdd&amp;quot; /add'&lt;br&gt;It will add the localgroup to the IIS_WPG group.&lt;br&gt;&lt;br&gt;Any questions just email me.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=76231" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#57311</link><pubDate>Thu, 14 Jul 2005 18:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:57311</guid><dc:creator>bernard</dc:creator><description>Hi Joshua,&lt;br&gt;&lt;br&gt;Nothing special, you can either use local or domain user. Assuming IIS is a a member server, you can add in those domain user to the WebOperator group. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=57311" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#57297</link><pubDate>Thu, 14 Jul 2005 12:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:57297</guid><dc:creator>bernard</dc:creator><description>I have IIS 6 on a server joint to a domain - I am trying to add a user to operate a web site but doesn't do anything - Any special steps that I have to do to make it work or just remove it from the domain.&lt;br&gt;&lt;br&gt;Thanks&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=57297" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#51358</link><pubDate>Thu, 09 Jun 2005 23:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:51358</guid><dc:creator>bernard</dc:creator><description>Hi Mike, &lt;br&gt;If you are in a domain, then of coz you need to use global group. As for the permissions, you can assign user/group at higher node and let the permissions get inherited for those child nodes.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=51358" width="1" height="1"&gt;</description></item><item><title>re: Configuring 'website operator' in IIS 6.0</title><link>http://msmvps.com/blogs/bernard/archive/2005/05/08/46074.aspx#50290</link><pubDate>Fri, 03 Jun 2005 10:24:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:50290</guid><dc:creator>bernard</dc:creator><description>Cant get this to work&lt;br&gt;&lt;br&gt;Local groups cannot be added to the iis_wpg group so i create a global group in AD.&lt;br&gt;&lt;br&gt;When adding permissions to lower level nodes you get the message that permission are inherited. Copy of Clear? If they realy are inherited allowing the group full controll at the top level node should do the trick, right?&lt;br&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=50290" width="1" height="1"&gt;</description></item></channel></rss>