Windows Server

How to add an account to the local IIS_IUSRS group


IIS_IUSRS is the group for IIS Worker Process Accounts. This means the identity that the application pool itself runs under. IUSR is the anonymous user identity. That means the identity that IIS believes to be the user who is accessing the site. This user is not a member of the IIS_IUSRS group by default. Kindly refer to the following related IIS guides. How to add and remove IIS Web Server on Windows Server 2019 via the Server Manager and PowerShell, Event ID 5059: Application pool has been disabled or Changing identity user for IIS Application Pool, how to create a self-signed certificate using PowerShell, how to configure SSL between WSUS upstream and downstream servers, and how to perform redirection from HTTP to HTTPS.

I needed to have the MBAM MBAM-RO-SVC account added to the local IIS_IUSRS group. The following steps below were how I approached it. 

Launch the Server Manager and click Tool and then on “Computer Manager.
Alternatively, you could also search from Computer Management from the start menu or from the "Windows Administrative Tools".

Adding accounts to IIS_IUSRS

This will open the Computer Management console. Navigate to the Local Users and Groups. Click on Groups and search for IIS_IUSRS and add the service account you created for the IIS Pool.

Local IIS group management

However, the account has been added. Click on Okay to finish the set up.


I hope you found this blog post helpful. Furthermore, Please let me know in the comment session if you have any questions.

Notify of

Inline Feedbacks
View all comments
Would love your thoughts, please comment.x