非管理员用户登录Web服务器认证失败,调整ISS文件夹权限仍未解决
Hey there, let's tackle this permission denied issue for non-admin users on your web server—since you've already tried adjusting folder and IIS user permissions, let's dive into less obvious but critical fixes:
Here are actionable steps to narrow down and resolve the problem:
Verify the Application Pool Identity’s Permissions
A common oversight is forgetting the application pool identity itself needs access to your web content. Head to IIS Manager:- Navigate to your site’s Application Pool → Advanced Settings → Identity
- If it’s set to
ApplicationPoolIdentity, add this identity to your web folder’s security permissions:- Right-click the web folder → Properties → Security → Edit → Add
- Type
IIS AppPool\[YourPoolName](replace[YourPoolName]with your actual pool name) → Check Names to confirm - Grant minimum required permissions: Read & Execute, List Folder Contents, and Read
Check NTFS Permission Inheritance
Restricted permissions on a parent folder might be overriding your web folder’s settings. Go to your web folder’s Properties → Security → Advanced. Ensure "Include inheritable permissions from this object's parent" is checked. If you enable this, apply changes and test access again.Review IIS Authentication Configuration
In IIS Manager, go to your site → Authentication:- If using Anonymous Authentication, confirm it’s set to use the application pool identity (not a restricted local user)
- If using Windows Authentication, make sure non-admin users have proper group memberships to access the site resources
Dig into Windows Event Logs
The Event Viewer will give you specific details about which user/resource is blocked. Open Event Viewer → Windows Logs → Application and System logs. Look for events from sources likeIIS-W3SVCorASP.NET—they’ll explicitly state which identity failed to access which file or folder.Test with a Fresh Non-Admin User
Create a new test non-admin user, add them to the IIS_IUSRS group (if relevant), then log in as this user to test the request. If it works, the original user might have account-specific restrictions; if not, the issue is rooted in server-wide permission settings.
内容的提问来源于stack exchange,提问作者Javier Flores

