Article ID: 909887 - Last Review: December 3, 2007 - Revision: 2.7 Error message when you try to view a Web site that is hosted on Internet Information Server 6.0 by using anonymous access: "401.1 Unauthorized: Logon failed"
On This PageSYMPTOMSWhen you try to view a Web site that is hosted on Microsoft Internet Information Server (IIS) 6.0 by using anonymous access, you may receive an error message that is similar to the following: 401.1 Unauthorized: Logon failed CAUSEThis problem may occur if one or more of the following conditions are true:
RESOLUTIONTo resolve this problem, make sure that the following conditions are true:
MORE INFORMATIONTo troubleshoot the issue effectively, make sure that “only” anonymous access is allowed on the Web site or on a single page. How to enable security logging on the Web serverIf you configure logon failure auditing, the Security event log may contain information to identify the cause of the error message. Logon failure auditing lets you view the errors in the Security event log. To enable security logging on the Web server, follow these steps:
Error examplesImportant This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows The following are examples of errors that may be logged in the Security event log. In these examples, username is the user account that is used for anonymous access. Error 1 Event Type: Failure Audit
Event Source: Security Event Category: Logon/Logoff Event ID: 534 Description: Logon Failure: Reason: The user has not been granted the requested logon type at this machine User Name: username Logon Type: 8 Logon Process: Advapi Authentication Package: Negotiate
Event Type: Failure Audit
Event Source: Security Event Category: Logon/Logoff Event ID: 530 User: NT AUTHORITY\SYSTEM Description: Logon Failure: Reason: Account logon time restriction violation User Name: username Logon Process: Advapi Authentication Package: Negotiate
Event Type: Failure Audit
Event Source: Security Event Category: Logon/Logoff Event ID: 532 User: NT AUTHORITY\SYSTEM Description: Logon Failure: Reason: The specified user account has expired User Name: username Logon Type: 8 Logon Process: Advapi Authentication Package: Negotiate
Event Type: Failure Audit
Event Source: Security Event Category: Logon/Logoff Event ID: 529 User: NT AUTHORITY\SYSTEM Description: Logon Failure: Reason: Unknown user name or bad password User Name: username Logon Type: 8 Logon Process: Advapi Authentication Package: Negotiate
Subauthentication enables IIS to authenticate the anonymous user without actually verifying the anonymous user password. Because anonymous access is provided to the content without authentication, the password is not required. Subauthentication enables IIS to use anonymous accounts without actually keeping valid user credentials in the metabase. When this setting is enabled, anonymous authentication works in IIS 5.0 compatibility mode. However, when the server is switched to IIS 6.0 Worker Process Isolation Mode, subauthentication is disabled because it requires a privileged process identity such as the Local System account. In this scenario, IIS 6.0 tries to log on by using the anonymous user credentials that are stored in the metabase. This behavior may cause a "401" error for the anonymous request if the user credentials that are stored in the metabase are not synchronized It may appear that switching into IIS 6.O Worker Process Isolation Mode breaks anonymous authentication. This condition may occur when subauthentication is configured in IIS. To verify whether subauthentication is enabled in IIS, open the Metabase.xml file in Notepad, and then search for the AnonymousPasswordSync property. If the AnonymousPasswordSync property is in the Metabase.xml file, delete the property, or set the value to False. Error 5 Event Type: Failure Audit
Event Source: Security Event Category: Logon/Logoff Event ID: 533 Description: Logon Failure: Reason: User not allowed to logon at this computer User Name: username Logon Type: 8 Logon Process: Advapi Authentication Package: Negotiate
REFERENCES
For more information about default permissions and user rights in IIS 6.0, click the following article number to view the article in the Microsoft Knowledge Base:
812614
(http://support.microsoft.com/kb/812614/
)
Default permissions and user rights for IIS 6.0
For more information about issues that may occur when you configure the AnonymousPasswordSync property in the IIS metabase, visit the following Microsoft Web site: http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/ac2075aa-6099-4f66-a6d7-cf9b3eef6f86.mspx
(http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/ac2075aa-6099-4f66-a6d7-cf9b3eef6f86.mspx)
For more information about how to configure subauthentication in IIS 6.0, visit the following Microsoft Web site:http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/bda0c6e5-ae71-463f-be27-f85dafa776b2.mspx
(http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/bda0c6e5-ae71-463f-be27-f85dafa776b2.mspx)
For information about how to use the Internet Information Services Authentication and Access Control Diagnostics (AuthDiag) Version 1.0 to troubleshoot authentication and authorization issues, visit the following Microsoft Web site:http://www.microsoft.com/windowsserver2003/iis/support/default.mspx
(http://www.microsoft.com/windowsserver2003/iis/support/default.mspx)
For more information about issues that may occur when the Security event log is full, click the following article number to view the article in the Microsoft Knowledge Base:
832981
(http://support.microsoft.com/kb/832981/
)
Users cannot access Web sites when the security event log is full
For more information about how to open the Domain Security Policy console or the Domain Controller Security Policy console at the command prompt, click the following article number to view the article in the Microsoft Knowledge Base: 832214
(http://support.microsoft.com/kb/832214/
)
"You may not have appropriate rights" error message when you try to open the Domain Security Policy console or the Domain Controller Security Policy console from the command prompt
For more information about issues that may occur when you modify the "Access This Computer from the Network" user right, click the following article number to view the article in the Microsoft Knowledge Base: 257346
(http://support.microsoft.com/kb/257346/
)
"Access This Computer from the Network" user right causes tools not to work
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
