Skip Navigation

IIST-SV-000159: Configure a global authorization rule

The IIS 10.0 web server must have a global authorization rule configured to restrict access.
To check compliance with IIST-SV-000159, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the IIS 10.0 web server name.
  3. Double-click the
    .NET Authorization Rules
    icon.
If any groups other than
Administrators
are listed, your server is not compliant.
If ASP.NET is not installed, this is not applicable. If the server is hosting Microsoft SharePoint, this is not applicable. If the server is hosting WSUS, this is not applicable.
If your server is not compliant, complete the following steps:
  1. Open the IIS 10.0 Manager.
  2. Click the IIS 10.0 web server name.
  3. Double-click the
    Authorization Rules
    icon.
  4. Remove all groups other than
    Administrators
    .