Reference Guide
...
Application Management
Application Triggers

Windows IIS Anonymous Authentication Strategy

This section will explain how to change the password of the user-defined for IIS Anonymous Authentication with the help of Application Configuration and Trigger.

WinRM service must be installed on those servers.

Users must have configured IIS information for this option and should have the below example.

IIS Anonymous Authentication Definition Screen
IIS Anonymous Authentication Definition Screen

IIS Anonymous Authentication Definition Screen
IIS Anonymous Authentication Definition Screen

IIS Anonymous Authentication- Specific User Definition Screen
IIS Anonymous Authentication- Specific User Definition Screen


For this option, an Application Trigger Config definition must be made first.

  1. Navigate to the Secrets > Configurations menu > Application Configuration.
Application Configuration Definition Screen
Application Configuration Definition Screen

  • Click the Add and the parameters must entered as described in the screen below.
Application Configuration Definition Screen
Application Configuration Definition Screen

  1. Windows IIS Anonymous Authentication is selected as the Strategy.
  2. IIS Anonymous Authentication will use WinRM service that’s why the user should enter WinRM port information.
  3. Select NTLM as the WinRM Authentication Method and press the Save button.
  4. After this definition, the user should open the Secrets >Application Management screen.
Application Management Definition Screen
Application Management Definition Screen

  • Click the Add button.

With this definition, when the Vault account's password is changed, reset, or updated, IIS Anonymous Authentication creates a trigger so that the password defined for the trigger is also automatically changed.

  • Enter the name of the trigger in the Name field.
  • Select the Application Configuration that defines the name above definition.
  • Enter the IIS Sites Name field from IIS which is described below the picture.
Windows IIS Default Pool Configuration Screen
Windows IIS Default Pool Configuration Screen

Application Configuration Screen
Application Configuration Screen

  1. Select the Vault Account that is defined in Password Vault and whose password we want to change.
  2. If the user defined for Password Vault is an authorized user to make changes on IIS, the Use Authentication User switch box is turned off. If it is not an authorized user, in this case, the Name and Password information of the Administrator user must be entered in the relevant fields.
  3. The Target Type value should be selected as Single Device.
  4. Select device information where IIS is installed and the device to be modified.
  5. If all values fields are entered user should click the Save button then the configuration will be completed.
Application Management - Application Trigger Definition Screen
Application Management - Application Trigger Definition Screen

  1. Navigate to the Vault Screen and select the Vault account.
Vault Screen
Vault Screen

  • Click the above picture button and a new popup will be shown below.
Vault Action Screen
Vault Action Screen


If Reset Password or Update Password is clicked, the system will change the password information from Windows Local User or Active Directory for the selected account. Additionally, a new Application Trigger record will be created to change the password from the IIS server.

The Application Management screen must be opened, and the defined record must be listed. To start this record and change the password from the IIS Site immediately, the Run button must be clicked. If not, the Application Trigger job will automatically run this record according to the defined period.

Application Management – Application Trigger Definition Screen
Application Management – Application Trigger Definition Screen