3.1 Anonymous User (anonymousUserName) - 'Virtual Dir Setting - AnonymousUserName = IUSR_'

Information

The principle of a non-privileged user is one that is running under least privilege, meaning they are non-admin users with limited functionality.

Solution

Make sure 'Anonymous User: anonymousUserName' is set to IUSR_(anyAlphaNumericSequenceHere) the 'IUSR' isn't case sensitive.

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: 2615d1efc073fd7c4071d0d7a5f2736d58913dedd7dd3391acdc04307e9746df