Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To protect an IIS 7.0 site, first choose how IIS will identify a request, then add URL authorization rules that allow only the intended users or groups. For a typical intranet, install Windows Authentication and IIS URL Authorization, disable Anonymous Authentication for the protected area, and allow a Windows group. Keep NTFS permissions in place: URL authorization does not replace file-system access controls.
This is a legacy guide for IIS 7.0 on Windows Server 2008 or Windows Vista. IIS configuration concepts and XML below are specific to IIS; exact IIS Manager and Windows feature-installation screens vary by operating system. Current Microsoft documentation may illustrate later Windows Server interfaces.
Authentication, authorization, and file permissions
These checks answer different questions:
- Authentication: Who made the HTTP request? IIS may accept an anonymous request or identify a Windows account, for example.
- URL authorization: Is that identity allowed to request this URL?
- Application and resource checks: Does the handler or application permit the operation, and can the relevant IIS worker-process or authenticated identity read the underlying file under NTFS permissions?
Passing one check does not guarantee access through the others. A URL rule cannot grant NTFS permission, and a permissive NTFS ACL does not override an IIS authorization denial.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsIIS 7 configuration is hierarchical: settings may come from server-level ApplicationHost.config and be inherited or overridden at site, application, directory, or URL scope. Whether a child can change a setting also depends on section locking. See Microsoft’s IIS 7 configuration-system overview.
#1 Best Overall
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Choose an authentication method
| Method | Good fit | Considerations |
|---|---|---|
| Anonymous | Public pages and files | Does not identify the visitor as an individual. IIS 7 enables it by default. |
| Windows | Intranets and environments using domain or local Windows accounts | Supports Windows identities and group-based rules. It is generally not the right sign-in experience for a public website. IIS 7’s default provider list includes Negotiate and NTLM; that does not guarantee Kerberos in a particular deployment. |
| Basic | Clients that support HTTP Basic Authentication | Credentials are Base64-encoded, not encrypted. Require HTTPS/TLS; do not enable it on an unprotected connection. |
| Digest | Some legacy environments needing challenge-response authentication | It does not encrypt the HTTP body. Use TLS when content confidentiality or integrity matters. |
| Client certificate mapping | Certificate-based client identity | Requires certificate provisioning, trust, and lifecycle management. |
| ASP.NET Forms Authentication | An ASP.NET application that provides its own login page and identity workflow | This is an application-level ASP.NET mechanism, not a native IIS authentication method. |
IIS 7 supports these native authentication schemes through separate features and configuration sections; the relevant role service or module must be installed. Read Microsoft’s authentication overview, Windows Authentication guidance, Basic Authentication guidance, and Digest Authentication guidance.
Install the required IIS features
Before configuring a method, confirm that its authentication role service is installed. Windows Authentication and Basic Authentication are not necessarily present in a default IIS 7 installation; Windows Authentication is disabled by default after its role service is installed. The IIS URL Authorization feature/module is a separate requirement.
On Windows Server 2008, use the server’s role-management tools to add the relevant IIS role services. On Windows Vista, use Windows Features to enable the IIS components available in that edition. Names and screen layouts vary, so verify that the specific authentication service and URL Authorization component are present in IIS Manager before proceeding. Do not mistake a current Server Manager path for the exact IIS 7-era interface.
Configure authentication in IIS Manager
- Open IIS Manager and select the server, site, application, or directory that contains the area you intend to protect. Choose the narrowest scope that matches the policy.
- Open Authentication in the IIS feature view.
- For a private area, select Anonymous Authentication and choose Disable. Leaving it enabled may allow requests to continue as the configured anonymous identity even when another authentication method is enabled.
- Select the intended method and choose Enable. For an intranet, this is often Windows Authentication. For Basic Authentication, first configure and enforce HTTPS.
- For Windows Authentication, inspect the providers only if your environment requires it. IIS 7 commonly lists
NegotiateandNTLM. Provider order and actual protocol negotiation depend on domain configuration, browser behavior, service principal names (SPNs), application-pool identity, proxies, and other deployment details.
Microsoft’s Windows Authentication instructions likewise require installing the role service, disabling Anonymous Authentication where Windows identity is required, and enabling Windows Authentication. See Windows Authentication in IIS.
Basic Authentication: require HTTPS
Enable Basic Authentication only when the site is protected by a correctly configured TLS certificate and HTTP is redirected to or otherwise prevented from carrying credentials. Base64 is an encoding, not encryption; anyone able to observe an unprotected request can recover the credentials. Configuring a Basic Authentication realm or domain does not make a plain HTTP connection safe. Microsoft’s Basic Authentication documentation describes the feature and its configuration.
Rank #2
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Add URL authorization rules in IIS Manager
- Select the same site or protected scope and open Authorization Rules.
- Review rules inherited from a parent. IIS commonly allows all users by default, so adding a narrow allow rule without removing the inherited broad allow may leave the area open.
- Remove or edit the broad rule as appropriate, then add an allow rule for the Windows user or group that should have access. Use a resolvable identity such as
CONTOSOWebAdminsorCONTOSOAlice. - Where useful, add a deny rule for anonymous users or constrain allowed HTTP verbs. Do not assume a verb restriction is a substitute for an identity rule.
- Test with an allowed account, a signed-in but unauthorized account, and an anonymous request. Also test the actual methods your application needs.
IIS URL Authorization is configured in system.webServer/security/authorization. Rules may be deployed in application Web.config files and affect content served through IIS at the URL layer. Microsoft explains its behavior in Understanding IIS URL Authorization and documents the authorization configuration section.
Configure authentication and authorization in Web.config
The following example disables anonymous access, enables Windows Authentication, removes the inherited all-users authorization rule, and allows a Windows group. Back up the existing configuration and place the rules at the intended scope. The authentication settings may be locked or restricted from application-level configuration on a particular server.
<?xml version="1.0" encoding="utf-8"?>
<configuration>
<system.webServer>
<security>
<authentication>
<anonymousAuthentication enabled="false" />
<windowsAuthentication enabled="true" />
</authentication>
<authorization>
<remove users="*" roles="" verbs="" />
<add accessType="Allow"
roles="CONTOSOWebAdmins" />
</authorization>
</security>
</system.webServer>
</configuration>
In IIS URL Authorization notation, * means all users and ? means anonymous users. Do not confuse these tokens with similarly named rules in ASP.NET authorization.
Allow one Windows user
<authorization>
<remove users="*" roles="" verbs="" />
<add accessType="Allow" users="CONTOSOAlice" />
</authorization>
Use a domain-qualified identity such as CONTOSOAlice or CONTOSOWebAdmins. For a local account, the corresponding form is typically SERVER01LocalUser. The server must be able to resolve the account or group.
Deny anonymous users
<authorization>
<add accessType="Deny" users="?" />
</authorization>
This explicitly denies anonymous requests. For a tightly controlled allow-list, removing inherited broad access and adding only intended allow rules is often clearer. Authentication configuration and authorization rules should agree about whether anonymous access is expected.
Rank #3
- 【Compatible with 30+ VPN service providers】Pre-installed with OpenVPN and WireGuard. OpenVPN speeds up to 150 Mbps; WireGuard speeds up to 355 Mbps. ***NO Wi-Fi function***
- 【Full Protection for Your Network】 Cloudflare encryption supported to protect the privacy. IPv6 security protocol supported. (To enable IPv6 function, please access to Admin Panel -> NETWORK -> IPv6.)
- 【Support VPN Cascading】Allow VPN server and VPN client operate simultaneously within the same device, enabling user to access local network servers with accessing public internet as a VPN client in the meantime.
- 【Ideal Gateway for Hosting a VPN Server at Home or Office】Access sensitive information stored under a corporate private network or access local files and bypass geo-blocking securely while working remotely.
- 【Advanced Hardware Specification】Equipped with 2.5 gigabit WAN port, 1 gigabit LAN port with USB 3.0 port, as well as 8 GByte EMMC (embedded multimedia card) storage for offline data storage.
Allow authenticated users
<authorization>
<remove users="*" roles="" verbs="" />
<add accessType="Allow" users="*" />
</authorization>
Use this only when requests are actually authenticated or anonymous users are otherwise denied. If Anonymous Authentication remains enabled, an anonymous request may not behave as the policy author intended.
Restrict allowed HTTP verbs
<authorization>
<remove users="*" roles="" verbs="" />
<add accessType="Allow" users="*" verbs="GET,HEAD" />
</authorization>
Verb restrictions are separate from identity restrictions. Test required operations such as POST, PUT, or application-specific methods before deploying a restriction.
Protect a directory or one URL
To protect an entire directory, place a Web.config file in that directory with the appropriate authorization section. Its rules inherit from the parent configuration, subject to section locking and rule evaluation.
To scope rules to one path, use a <location> element in a configuration file above that path. The path is relative to the configuration scope:
<configuration>
<system.webServer>
<security>
<authorization>
<remove users="*" roles="" verbs="" />
<add accessType="Allow" roles="CONTOSOWebAdmins" />
</authorization>
</security>
</system.webServer>
<location path="secure/report.aspx">
<system.webServer>
<security>
<authorization>
<clear />
<add accessType="Allow" users="CONTOSOAlice" />
</authorization>
</security>
</system.webServer>
</location>
</configuration>
<remove> removes a matching inherited rule, while <clear> clears the inherited collection before adding the rules shown. Choose deliberately: clearing can remove other inherited policy you meant to preserve. A child rule is not a universal override for a parent deny rule; IIS inheritance and deny-first evaluation can produce access denials that a child allow does not undo.
Recommended Free Tools
Rank #4
- APPLIANCE ONLY: Hardware unit sold without a service subscription — security services, firmware updates and support are NOT included and must be purchased separately to activate protection.
- PERFORMANCE: Up to 2.5 Gbps firewall inspection, 1 Gbps threat prevention and 1.2 Gbps IPSec VPN throughput driven by SonicWall's patented Reassembly-Free Deep Packet Inspection (RFDPI) engine.
- CONNECTIVITY: 8x1GbE + 2x1G SFP in a desktop form factor; zero-touch deploy and manage on-box or via cloud Network Security Manager (NSM).
- THREAT PROTECTION: SonicOS 8 delivers intrusion prevention, gateway anti-malware, application control, TLS/SSL decryption, Capture ATP multi-engine sandboxing (RTDMI) and reputation-based content & DNS filtering with an active service subscription.
- BUILT FOR SMALL BUSINESS & BRANCH: Secure SD-WAN, IPSec and SSL VPN plus Zero-Trust Network Access through Cloud Secure Edge keep distributed sites and remote workers protected.
Set configuration with AppCmd.exe
AppCmd.exe, included with IIS 7, can configure and inspect IIS settings. Run it from an elevated command prompt on the IIS server. The tool is under %systemroot%system32inetsrv.
For a site named Contoso, disable anonymous access and enable Windows Authentication:
appcmd.exe set config "Contoso" ^
-section:system.webServer/security/authentication/anonymousAuthentication ^
/enabled:"False" /commit:apphost
appcmd.exe set config "Contoso" ^
-section:system.webServer/security/authentication/windowsAuthentication ^
/enabled:"True" /commit:apphost
To enable Basic Authentication instead, use it only with HTTPS:
appcmd.exe set config "Contoso" ^
-section:system.webServer/security/authentication/basicAuthentication ^
/enabled:"True" /commit:apphost
Add an allow rule for a Windows group:
appcmd.exe set config "Contoso" ^
-section:system.webServer/security/authorization ^
/+"[accessType='Allow',roles='CONTOSOWebAdmins']"
Adding that rule does not necessarily remove an inherited allow-all rule. Inspect and adjust the authorization collection at the intended scope before treating the site as protected.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute/commit:apphost writes the configuration into the appropriate location section of ApplicationHost.config. The commit target determines the level where a setting is stored; choose it to match your intended scope rather than assuming the command writes to the site’s Web.config. AppCmd also supports other commit targets, including site and app, depending on the configuration operation and scope. Consult Microsoft’s AppCmd guide and IIS security configuration examples for syntax and behavior.
Best Value
- SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
- Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
- Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
- Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
- Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
To inspect effective configuration, AppCmd can display a section at a site scope, for example:
appcmd.exe list config "Contoso" -section:system.webServer/security/authorization
If you need a change made at a different level, verify the effective configuration after the command. A configuration section may be locked; an administrator can unlock it at the appropriate level or make the change where policy permits. Do not unlock a section merely to bypass a deliberate server-wide policy.
IIS URL Authorization versus ASP.NET authorization
| IIS URL Authorization | ASP.NET URL authorization | |
|---|---|---|
| Configuration section | system.webServer/security/authorization |
system.web/authorization |
| Implementing module | IIS URL Authorization module | ASP.NET UrlAuthorizationModule |
| Coverage | Applies at the IIS URL layer to content handled by IIS, including static content | Applies through the ASP.NET pipeline to managed requests; it is not a substitute for protecting static files at the IIS layer |
| Typical identity | May use Windows identities or identities supplied by application authentication components | Commonly used with ASP.NET Forms Authentication, membership, and roles |
| Typical use | Protecting a URL or content regardless of whether it is served by an ASP.NET handler | Application-specific access decisions for ASP.NET pages and resources |
These sections are not interchangeable. A rule in system.web/authorization does not automatically protect every static file, while IIS URL Authorization does not replace application checks or NTFS permissions. Forms Authentication usually handles an ASP.NET login workflow and identity; it is not a native IIS authentication scheme. IIS URL Authorization can also work with non-Windows identities when the application supplies an appropriate identity through membership, roles, or a custom authentication module. See Microsoft’s explanation of IIS URL Authorization.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Troubleshoot common failures
| Symptom | What to check |
|---|---|
| 401 response or repeated sign-in prompt | Confirm the authentication role service is installed and enabled; check credentials, domain trust, browser policy, Windows provider negotiation, and the user’s permissions. If Windows Authentication works locally but not remotely, investigate SPNs, Kerberos/NTLM behavior, proxy settings, and domain connectivity. |
| Anonymous users still reach a supposedly private URL | Check that Anonymous Authentication is disabled at the effective scope or explicitly denied, and inspect inherited allow rules. Enabling Windows or Basic Authentication alone does not necessarily turn off anonymous access. |
| Signed-in user gets 403 or access denied | Check the allow/deny rules, whether the user belongs to the named group, identity spelling and domain, parent-level denies, and effective configuration. Then verify NTFS read permissions for the identity or worker-process access model used by the request. |
Web.config causes a configuration error |
Validate XML and section names; confirm the feature is installed; check whether the section is locked or unsupported at that scope. A locked section must be configured at an allowed level or deliberately unlocked by an administrator. |
| Windows Authentication works on the server but not for remote clients | Check browser intranet-zone settings, domain reachability, SPNs, provider negotiation, proxies, and whether the application requires delegation or a second-hop identity. Negotiate in the provider list does not prove that Kerberos is being used. |
| Basic credentials appear exposed | Stop sending credentials over HTTP. Configure valid TLS and enforce HTTPS for the protected endpoint. |
| An ASP.NET rule has no effect on a static file | Use IIS URL Authorization in system.webServer/security/authorization when the file must be protected at the IIS URL layer. |
| A child folder’s allow rule does not grant access | Inspect parent denies and inherited rules, and check whether the section is locked. A child allow does not necessarily override a parent denial. |
Use IIS logs to confirm the response and requested URL, and application logs for managed-content decisions. A 401 commonly points to authentication or access checks, while a 403 often indicates that the request was understood but denied; neither status alone identifies the exact cause.
Quick Recap
Security checklist
- Install only the authentication services and modules you need.
- Use HTTPS for Basic Authentication; use TLS for confidential content even when using Digest.
- Disable Anonymous Authentication for areas that must require a known identity.
- Use least-privilege users or groups and apply rules at the narrowest practical scope.
- Review inherited rules before adding an allow rule; verify that no broad allow remains.
- Keep IIS authorization, application authorization, and NTFS permissions aligned.
- Test allowed, denied, anonymous, and unauthenticated cases, as well as required HTTP verbs.
- Treat deployed
Web.configfiles as security-sensitive: a release can change access policy. - Do not change Windows Authentication providers or unlock configuration sections without understanding the server’s domain and policy requirements.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

