Keep IIS7 Failed Request Tracing as a sysadmin only diagnostic tool?

Posted by Kev on Server Fault See other posts from Server Fault or by Kev
Published on 2011-02-04T16:11:22Z Indexed on 2011/02/07 15:26 UTC
Read the original article Hit count: 540

I'm giving some of our customers the ability to manage their sites via IIS Feature Delegation and IIS Manager for Remote Administration.

One feature I'm unsure about permitting access to is Failed Request Tracing for the following reasons:

  • Customers will forget to turn it off
  • The server will be taking a performance hit (especially if 500 sites all have it turned on)
  • The server will become littered with old FRT's
  • The potential to leak sensitive information about how the server is configured thus providing useful information to would-be intruders.

Should we just keep this as a troubleshooting tool for our own admins?

© Server Fault or respective owner

Related posts about windows-server-2008

Related posts about iis7