Skip Navigation

IIST-SV-000156: Assign passwords

All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.
To check compliance with IIST-SV-000156, complete the following steps:
  1. Access the IIS 10.0 web server.
  2. Access the
    Apps
    menu.
  3. Under
    Administrative Tools
    , click
    Computer Management
    .
  4. In the left pane, expand
    Local Users and Groups
    .
  5. Click
    Users
    .
  6. Review the local users displayed in the middle pane.
  7. If any local accounts are present and used by IIS 10.0, verify with your System Administrator that the default passwords have been changed.
If passwords have not been changed from the default, your server is not compliant.
If your server is not compliant, complete the following steps:
  1. Access the IIS 10.0 web server.
  2. Access the
    Apps
    menu.
  3. Under
    Administrative Tools
    , click
    Computer Management
    .
  4. In the left pane, expand
    Local Users and Groups
    .
  5. Click
    Users
    .
  6. Change the password for any local accounts displayed that are used by IIS 10.0.
  7. Verify with your System Administrator that the default passwords have been changed.