Quantcast
Channel: sharepoint.H@ck
Viewing all articles
Browse latest Browse all 15

Windows Server 2008 R2 and Blank Central Admin Sites, IIS_IUSRS

$
0
0

So got another interesting issue where a mate of mine said that after installing SharePoint 2007 on Windows Server 2008 R2 that they were unable to see the CA site. The interesting part is that there were no errors and viewing the source of the site showed ony beginning and ending HTML tags.

I recalled that this environment was installed using "Least Privileged" account mode (no local admin access being one section). So away I go and boot my 2008 R2 VM, configure the same security setting, and what do you know: a blank CA site.

Through the use of process monitor (monitored the w3wp.exe) and some digging I found that the issue had to do with the Application Pool account for CA not being to execute with impersonation. Seems like the default local policy on Windows Server 2008 removed the IIS_IUSRS group (used by IIS7 and above) from the list of accounts / groups allowed to run with impersonation.

Adding the IIS_IUSRS group / the CA app pool account fixed this issue.

To get the the right policy permission: Start -> Programs -> Administrative Tools -> Local Policy -> Security Settings -> User Rights Assignment (Note: you need domain admin rights to modify this).

Oh, this was due to Group Policy changes and not by default design!


Viewing all articles
Browse latest Browse all 15

Trending Articles