IIS WebDav hosting using IIS Manager Users to authentication

Enabling IIS WebDav functionality by using IIS Manager Users

Setting up IIS WebDav functionality is pretty trivial if one to rely on Windows user accounts for authentication but this architecture causing massive issues, namely:

  1. Accounts have to be precreated in Windows and are in fact real Windows accounts with permissions through system. I frequently see people while troubleshooting WebDav authentication issues adding those users to various group (in addition to default Users group) including Administrators account.
  2. It’s difficult to maintain since those users accounts are specific to machine where they live and hence not trivial to extend setup to several servers without keeping all accounts in sync.
Instead we can rely on IIS Manager to store and maintain users which was designed to allow hosting providers to provide remote IIS management functionality to customers. This setup remove all the drawbacks of using Windows users as authentication provider. It’s easily scalable (since IIS shared configuration can be used) and do not provide any sort of access to underlying operating system.
Solution consists of 2 DSC scripts below. Instead of using UI to set this up DSC was chosen since it’s easily replicated at scale and provide reproducible and consistent behavior.
Prerequisites.ps1 which performs following:
  1. Install basic IIS features
  2. Enabled remote management to enable IIS Manager User features
  3. Install Nuget and chocolatey providers to pull required DSC resources to create website and manipulate NTFS permissions

Startup.ps1 which performs following:

  1. Enables WebDav and neccessary features
  2. Configured IIS Manager to accept both Windows and IIS Manager credentials
  3. Modifies permissions to allow IIS_IUSRS users to read configuration file
  4. Creates website and bindings it to default ports
  5. Create IIS manager users with the password
  6. Modifies IIS configuration to allow WebDav publishing based off IIS Manager credentials provider
  7. Assigns WebDav permissions to newly created users to access website