You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IIS虚拟目录身份验证异常问题求助

IIS虚拟目录Windows身份验证401.2故障排查求助

环境配置

  • 基于Hyper-V,通过AutomatedLab搭建Active Directory域测试环境,域名为CONTOSO
  • Web服务器:web1.contoso,测试IIS虚拟目录功能

身份验证层级配置

  • 服务器级:仅启用匿名身份验证(其余身份验证方式禁用)
    • 默认网站:仅启用匿名身份验证(其余身份验证方式禁用)
      • 虚拟目录example:仅启用Windows身份验证(其余身份验证方式禁用)
  • Windows身份验证提供商顺序:NTLM、Negotiate
  • 应用池配置:默认网站与虚拟目录均使用DefaultAppPool,池身份为ApplicationPoolIdentity

文件系统权限

虚拟目录对应服务器路径c:\example,设置无继承权限如下:

用户/组权限实体说明
ConfigManagement读/写AD域组,包含所有配置管理用户
IIS_IUSRS读IIS内置用户组
Administrators (WEB1\Administrators)读/写服务器本地默认管理员组
System读/写系统内置组
Users (WEB1\Users)读/写服务器本地默认用户组

问题现象

  1. 以服务器管理员身份远程登录web1.CONTOSO,访问该虚拟目录可正常查看index.html文件
  2. 在Windows 10虚拟机client1.CONTOSO上,使用属于ConfigManagement组的域普通用户访问https://web1.CONTOSO/example时,反复弹出凭据输入窗口;取消后浏览器返回401.2未授权错误
  3. 查看失败跟踪日志,发现系统未按配置执行Windows身份验证,验证流程失败
  4. 已尝试将网站及服务器级身份验证改为Windows身份验证,并重启web1.CONTOSO服务器,问题仍未解决

附:虚拟目录Web.config配置

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
    <system.webServer>
        <security>
            <authentication>
                <anonymousAuthentication enabled="false" />
                <windowsAuthentication enabled="true">
                    <providers>
                        <clear />
                        <add value="NTLM" />
                        <add value="Negotiate" />
                    </providers>
                </windowsAuthentication>
            </authentication>
        </security>
        <tracing>
            <traceFailedRequests>
                <remove path="*" />
                <add path="*">
                    <traceAreas>
                        <add provider="ASP" verbosity="Verbose" />
                        <add provider="ASPNET" areas="Infrastructure,Module,Page,AppServices" verbosity="Verbose" />
                        <add provider="ISAPI Extension" verbosity="Verbose" />
                        <add provider="WWW Server" areas="Authentication,Security,Filter,StaticFile,CGI,Compression,Cache,RequestNotifications,Module,FastCGI,WebSocket" verbosity="Verbose" />
                    </traceAreas>
                    <failureDefinitions timeTaken="00:00:00" statusCodes="200-999" />
                </add>
            </traceFailedRequests>
        </tracing>
    </system.webServer>
</configuration>

虚拟目录Windows身份验证设置说明

已启用Windows身份验证,提供商顺序为NTLM、Negotiate,其余身份验证方式均已禁用。

内容的提问来源于stack exchange,提问作者moosearch

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 06:53:34