Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

IIS performance tuning is not a hunt for a magic queue length or recycling schedule. The reliable approach is to establish a baseline, identify whether the limit is IIS, the application, or infrastructure, change one variable, and measure the same workload again.

This guide applies primarily to IIS 10.0 on supported Windows Server releases, including Windows Server 2016, 2019, 2022, and 2025. Labels, defaults, modules, and hosting behavior can differ by release and by whether you run classic ASP, ASP.NET Framework, ASP.NET Core, PHP/FastCGI, or static content.

What “IIS performance” actually means

Look beyond average response time. A useful performance picture includes:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Latency: time for one request to complete.
  • Tail latency: p95, p99, or p99.9 response time, where user-visible slowdowns usually appear.
  • Throughput: requests or bytes served per second.
  • Concurrency: requests handled at once.
  • Availability: successful responses rather than timeouts and 5xx errors.
  • Efficiency: CPU, RAM, disk, network, and database resources consumed per request.

A server with a lower average latency but growing queues and 503 responses is not faster in any useful operational sense.

Separate an IIS bottleneck (queueing, modules, compression, worker-process starvation or disk pressure) from an application bottleneck (slow SQL, locks, synchronous I/O, garbage collection or remote APIs) and an infrastructure bottleneck (VM sizing, storage, DNS, TLS, load balancer or network limits). IIS settings cannot repair an application that spends most of its time waiting for SQL Server.

Microsoft’s architecture and tuning guidance is documented in Tuning IIS 10.0.

Understand the request path

  1. HTTP.sys accepts the connection, handles routing and may return a response from its kernel-mode cache.
  2. Other requests are dispatched to an IIS worker process (w3wp.exe) in an application pool.
  3. IIS modules and handlers run, then the application may call a database, API, file system or another service.
  4. The response can be compressed and cached before it reaches the client.

A public, cacheable response served by HTTP.sys can use far fewer user-mode resources than a personalized request traversing the entire pipeline. Never cache account pages, carts or authorization-sensitive responses as shared content. Incorrect cache variation can expose private data or serve stale content. Modules and filters that are not cache-aware can also prevent effective caching.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 1: Establish a repeatable baseline

Record the environment

  • Windows Server edition and version; IIS version and installed role services.
  • CPU count and, where relevant, NUMA layout; RAM and storage volumes.
  • Application pools, runtime/framework, process architecture and dependencies.
  • Traffic volume, peak periods, load balancer/CDN/WAF placement and deployment schedule.

Record measurements

Capture average, p95 and p99 latency; requests per second; status-code distribution; 4xx/5xx rate; application-pool queue length; CPU; available memory and paging; disk latency and queue length; network throughput; and database or downstream-service timing. IIS logs, HTTP.sys logs, Failed Request Tracing, Windows counters and application telemetry are complementary evidence, as explained in Microsoft’s IIS troubleshooting module.

These commands are starting points, not a complete monitoring system:

Get-Counter 'Processor(_Total)% Processor Time',
            'MemoryAvailable MBytes',
            'LogicalDisk(_Total)Avg. Disk sec/Read',
            'LogicalDisk(_Total)Avg. Disk sec/Write',
            'Web Service(_Total)Current Connections',
            'Web Service(_Total)Get Requests/sec',
            'Web Service(_Total)Bytes Total/sec' -SampleInterval 5 -MaxSamples 60

Get-Process w3wp | Select Id,ProcessName,CPU,WorkingSet64,PrivateMemorySize64
%windir%system32inetsrvappcmd list wp

Do not change queue limits, cache sizes, recycling, compression or process architecture until you know what is slow, when it is slow, which requests are affected and which resource saturates first.

Step 2: Find the bottleneck

Symptom Investigate first
High CPU, little queueing Application code, dynamic compression, encryption, modules or request volume
High CPU and high latency CPU-bound code, compression overhead or insufficient capacity
High memory Leaks, oversized caches, too many pools, large objects or 32-bit address-space limits
Rising queue and 503s Blocked threads, slow dependencies, unhealthy worker process or insufficient capacity
High disk latency Logs, content, antivirus scanning, database or compression-cache contention
Slow only after recycle Cold startup, JIT, cache warming or connection initialization
Only dynamic pages are slow Application, database, external APIs, session locks or thread starvation

Low-risk improvements

Cache deliberately

Use browser/CDN/IIS output caching for public, correctly varied responses. Version immutable CSS, JavaScript, images and fonts so they can have long lifetimes; define invalidation for HTML and API responses. Check authorization, cookies, language, encoding and other cache-key dimensions. IIS exposes settings such as enabled, enableKernelCache, maxCacheSize and maxResponseSize; Microsoft documents 262,144 bytes as a documented default maximum for some user-mode and HTTP.sys cache entries, but effective values can differ by configuration.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Distinguish HTTP cache headers from IIS output caching, application data caching and CDN caching. A larger cache consumes RAM; increase it only when cache misses are expensive and the working set is understood.

Compress the right content

Static compression is usually valuable for HTML, CSS, JavaScript, JSON, XML and SVG. JPEG, PNG, WebP, AVIF, MP4, ZIP and GZIP are already compressed and generally gain little. Dynamic compression reduces transfer size but consumes CPU, so test it with realistic payloads and concurrency. Verify that clients send Accept-Encoding, responses contain the expected Content-Encoding, and variation is handled correctly.

Static and dynamic compression are separate IIS features; see HTTP Compression. Brotli is an installable IIS compression extension, not a guaranteed default on every server; confirm module availability, proxy behavior and CPU impact using Microsoft’s compression overview.

Keep useful logging

Logging reveals slow URLs, status patterns, bytes, traffic windows and deployment correlations. Configure fields, rollover, retention and storage deliberately through Server or site → Logging. Move logs off a contended volume where practical and monitor disk-full conditions. Do not disable logging as a first-line optimization; reduce unnecessary fields or use central binary logging when many URL groups make formatted files expensive. Configuration details are in HTTP Logging.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Tune application pools with evidence

Isolation: Separate pools improve fault and runtime isolation but duplicate processes and caches, consuming RAM. Use fewer pools on memory-constrained servers when workloads are compatible.

Queue length: The documented default is 1,000. When the limit is exceeded, IIS rejects requests with 503. A larger queue does not make work faster; it only lets more requests wait. Increase it only for short, expected bursts that the backend can drain before client or proxy timeouts. Never use it to hide a deadlock, saturated CPU or slow database.

%windir%system32inetsrvappcmd list apppool "DefaultAppPool" /text:queueLength
%windir%system32inetsrvappcmd set apppool "DefaultAppPool" /queueLength:2000

The value 2000 is an example, not a recommendation.

32-bit mode: enable32BitAppOnWin64 can satisfy legacy dependencies and may reduce memory use, but a 32-bit process has roughly a 4 GB user-mode address-space ceiling. Use it only when compatibility or testing justifies it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Containlol 6 Pcs Waiter Book Server Organizer with Pocket,Classic Style
  • Adequate quantity: we have prepared 6 pieces of server books with zipper pocket in the package, sufficient quantity can easily satisfy your daily use and replacement requirements, making your work more efficient and convenient
  • Abundant capacity: with 8 pockets design, including the credit card holder, window viewer, receipt pocket, vertical zipper pocket, order pad holder sleeve and pen holder, this waiter book can help you organize items separately and methodically
  • Fine workmanship: our serving book is made of quality PU leather, with a protective clear coating layer, sturdy and reliable, not easy to stain, tear or fade, smooth on surface, providing you with a nice use experience, and can serve you for a long time
  • Proper size and portable: each black server book measures around 8.07 x 4.92 x 0.39 inches in closure size, and its expansion size is around 10.35 x 4.92 inches, a suitable size for most people, and you can put it in your pocket for use
  • Versatile applications: this server wallet can be widely adopted for serving, cleaning, gardening, cooking, baking, crafting and more; In addition, it can hold various small tools, such as check pads, napkins, cards, pens, recipe cards, menus and so on

Recycling: IIS documents a 29-hour periodic default, with memory, private-memory and request-count thresholds disabled by default. Recycling can contain leaks or unhealthy processes but causes cold caches, startup/JIT work and connection re-establishment. It is not a speed boost or a substitute for fixing a leak. Schedule predictable recycles off-peak, verify overlapping-recycle behavior, and measure first-request latency.

Idle timeout: Short timeouts save memory but create cold starts. A long timeout or preload/AlwaysRunning reduces startup latency at a RAM cost; choose based on traffic and startup expense.

Remove only unnecessary modules

Inventory modules and handlers before removing anything. Each active module can add pipeline work, but a minimal static-site list is not suitable for an application needing authentication, URL rewriting, WebSockets, managed code or custom handlers. Back up configuration and test routing, authentication, error handling, compression and deployment afterward.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Diagnose slow and failed requests

Use Failed Request Tracing when ordinary logs show a slow or failing request but not the cause. Enable the role service, create a narrow rule for a status code such as 500/503 or a duration threshold, reproduce the issue, inspect the trace, then disable or narrow tracing and remove old files. The default directory is %SystemRoot%inetpublogsFailedReqLogFiles. Broad production tracing can create substantial files and may capture sensitive request details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For static-heavy sites, inspect storage latency, antivirus scanning, log contention, cache headers, file layout and CDN suitability. The advanced allowSubDirConfig setting can help very large random static-content trees by limiting searches for lower-level configuration files, but it can break applications relying on nested web.config files.

Best Value
Brinero Professional Server Book for Waitress, Dual Core Deluxe Server Book Organizer for a Sturdy Surface, Metal Corners, Server Book - Waitress Book Organizer - Server Books for Waitress
  • 100% Satisfaction Warranty – Our servers book for waitress organization are handcrafted with elegant stitching that lasts. We take pride in offering our customers a waitress book made to exceptional quality standards. To ensure satisfaction, every waiters checkbook is backed by a 1-YEAR WARRANTY. If you are not 100% SATISFIED for any reason we will send you a replacement. No Questions Asked
  • Holds up under Pressure – When you're taking orders the last thing you need is a flimsy waiter book that keeps bending. Our 8”x5” server books for waitress organization is the only one with a premium reinforced dual inner core. Providing an unmatched sturdy reliable writing surface that will last for years
  • On Another Level – Halt the endless cycle of replacing your cheap thin black server book that barely lasts a week. This serving book for waitresses can become your permanent partner. Crafted with overwhelmingly strong attention to detail, the waiter checkbook offers an unparalleled value that you won’t regret investing in
  • Scribble In Style – Impression is everything. You’re making a statement when you bring out this sleek vegan leather serving book. Our serving books have no logos or images and exquisite stitching for a professional feel your colleagues will envy
  • Stay Calm and Collected – Whether you have 1 table or 7, organization is key. This server checkbook has 9 versatile pockets including a durable metal zipper to keep your cash secure. Stay on top of everything with this deluxe server book organizer and bring superior service to every customer

Avoid frequently creating and deleting CGI processes. FastCGI or another persistent process model reduces creation overhead. PHP/FastCGI process counts, timeouts, recycling, memory limits, opcode caching and database latency must be sized from workload measurements rather than a universal number.

Safe inspection and rollback commands

%windir%system32inetsrvappcmd add backup BeforePerformanceChanges
%windir%system32inetsrvappcmd list apppool
%windir%system32inetsrvappcmd list apppool "DefaultAppPool" /text:*
%windir%system32inetsrvappcmd list site
%windir%system32inetsrvappcmd list wp
Import-Module WebAdministration
Get-ChildItem IIS:AppPools | Select Name,State
Get-ItemProperty IIS:AppPoolsDefaultAppPool |
  Select queueLength,enable32BitAppOnWin64

Back up configuration before production edits. Record the old value, new value, reason, test result and rollback command. Change one variable at a time.

A practical tuning sequence

  1. Write a measurable problem, such as “p95 exceeds 800 ms from 10:00–11:00” or “503s occur during bursts.”
  2. Correlate IIS logs, counters, tracing and application/database telemetry.
  3. Fix application and database inefficiencies before server-level work.
  4. Correct cache headers, then test static compression and dynamic compression separately.
  5. Remove only proven-unnecessary modules.
  6. Choose pool isolation, idle and recycle policies from memory and startup evidence.
  7. Adjust queue length only when queue behavior and timeout budgets justify it.
  8. Load-test cold and warm states, cache hits and misses, authenticated and anonymous paths, dependencies and recycle events.
  9. Compare p50/p95/p99 latency, throughput, errors, queue, CPU, memory, disk, network and downstream timings.

When IIS tuning is not enough

Move to application profiling, database tuning, CDN or reverse-proxy caching, load balancing, scale-out or managed hosting when one server remains resource-bound, maintenance requires high availability, users are geographically distributed or static bandwidth dominates. ASP.NET Core behind IIS also requires runtime, Kestrel, database and proxy tuning; IIS alone is not the whole stack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Built-in IIS logs, Performance Monitor, AppCmd, PowerShell, Event Viewer and Failed Request Tracing are sufficient for many small deployments. Commercial tools become useful when you need centralized dashboards, alerting, historical capacity data, distributed traces or multi-server visibility.

Production checklist

  • Baseline and workload definition recorded.
  • Configuration backed up.
  • One change made and its trade-off understood.
  • Representative load test completed.
  • p95/p99 latency and error rates compared with baseline.
  • CPU, memory, disk, network, queue and dependency timing checked.
  • Rollback documented and monitoring/alerts enabled.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.