1.1 Default Install Files - 'iisadmpwd' Check if using Integrated Windows Authentication

Information

6. Restrict access to iisadmpwd Virtual Directory to Windows Authenticated users if it exist or remove the virtual directory mapping. Removing unnecessary files and folders will help to reduce attack surface thus mitigating unnecessary attack vectors.

Solution

Make sure 'iisadmpwd' does not exist or access is restricted to Windows Authenticated users.

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: 7b53c4f18a0a8dc18455a376e6a81a4ee6c88d0a5746e0f022f42276c67a3add