Article ID: 324333 - Last Review: July 7, 2008 - Revision: 7.1 PRB: 401 Error message if user is not included in the Bypass Traversal Checking policyThis article was previously published under Q324333 We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 7.0 running on Microsoft Windows Server 2008. IIS 7.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site: http://www.microsoft.com/technet/security/prodtech/IIS.mspx
(http://www.microsoft.com/technet/security/prodtech/IIS.mspx)
For more information about IIS 7.0, visit the following Microsoft Web site: http://www.iis.net/default.aspx?tabid=1
(http://www.iis.net/default.aspx?tabid=1)
On This PageSYMPTOMS When you connect to any page on an Internet Information
Services (IIS) Web site, you may receive the following error message:
401.3 Unauthorized due to ACL on resource
CAUSE This can occur if the account that is trying to access
resources on the server does not have enough NTFS file system permissions on
the resource. RESOLUTION Do not remove the Everyone group from the Bypass Traverse
Checking policy. If the Everyone group must be removed from the policy for
security reasons, make sure that the IUSR account is listed in the policy.
STATUSThis
behavior is by design. MORE INFORMATIONSteps to reproduce the behavior
REFERENCES
For more information, click the following article numbers to view the articles in the Microsoft Knowledge Base:
812614
(http://support.microsoft.com/kb/812614/
)
Default permissions and user rights for IIS 6.0
271071
(http://support.microsoft.com/kb/271071/
)
How to set required NTFS permissions and user rights for an IIS 5.0 Web server
187506
(http://support.microsoft.com/kb/187506/
)
Required NTFS permissions and user rights for IIS 4.0
| Article Translations
|
Back to the top
