Securing your web server against attacks is one of the most important jobs the network administrator can do.  Blackbaud can not be held responsible for any unauthorized access to your web server.  It is highly recommended that you consult with a professional Internet Security engineer to ensure you have fully secured your web server.  Please review the attached links from Microsoft for basic information on securing Microsoft Web Servers.

http://microsoft.com/technet/security/tools.asp
http://msdn.microsoft.com/security/securecode/webservices/default.aspx

Note: We provide links to third-party websites in an effort to help you resolve your issue. We are not responsible for the information on third-party websites, and we cannot assist in implementing the solutions on these websites.

NTFS permissions

For Faculty Access for the Web version 7 File and Directory Permissions, please refer to the Administration Guide for Faculty Access for the Web. Listed below is a table referencing necessary NTFS permissions for the BBFEWebGroup on the Web server. Permissions include Read (R), Read and Execute (X), Write (W), and Modify (M).

For an easier way to configure your NTFS permissions, try the Permflash utility. 

Note: If using Windows Authentication for SQL Server, complete these additional steps.

To set permissions review the table that correspond to your FAWEB version:


 

If you are using version 7.82 or higher:

Directory Directory PermissionsFile Permissions Windows 2003 User or GroupWindows 2008 User
The Financial Edge FolderRXRXBBFEWebGroupIUSR
The Financial Edge/SysDBfolderRXWRXWBBFEWebGroupIUSR
FAWeb7RXRXBBFEWebGroupIUSR
System TempRXWRXWBBFEWebGroupIUSR
Program Files\Common Files\BlackbaudRXRXBBFEWebGroupIUSR
The Financial Edge\SysDB folderRXWRXWNetwork ServiceNetwork Service
BBWebClient folderRXRXNetwork ServiceNetwork Service
\Program Files\Blackbaud\Downloadable DocumentsRXWM RXWMNetwork ServiceNetwork Service
\Program Files\Blackbaud\FAWEB7\PDFRXWRXWNetwork ServiceNetwork Service





If you are using version 7.75 through 7.80:

Directory Directory PermissionsFile Permissions Windows 2003 User or GroupWindows 2008 User
All parent folders of Faculty Access for the WebRRBBFEWebGroupIUSR
The Financial Edge FolderRXRXBBFEWebGroupIUSR
The Financial Edge/SysDBfolderRXWRXWBBFEWebGroupIUSR
FAWeb7RXRXBBFEWebGroupIUSR
System 32RRBBFEWebGroupIUSR
System TempRXWRXWBBFEWebGroupIUSR
Program Files\Common Files\BlackbaudRXRXBBFEWebGroupIUSR
Program Files\Common Files\SystemRXRXBBFEWebGroupIUSR
The Financial Edge\SysDB folderRXWRXWNetwork ServiceNetwork Service
BBWebClient folderRXRXNetwork ServiceNetwork Service
\Program Files\Blackbaud\Downloadable DocumentsRXWM RXWMNetwork ServiceNetwork Service
\Program Files\Blackbaud\FAWEB7\PDFRXWRXWNetwork ServiceNetwork Service




If you are using version 7.71 or lower:

Directory Directory PermissionsFile Permissions User or Group
All parent folders of Faculty Access for the WebRRBBFEWebGroup
The Financial Edge FolderRXRXBBFEWebGroup
The Financial Edge\SysDBfolderRXWRXWBBFEWebGroup
FAWeb7 folderRXRXBBFEWebGroup
System 32RRBBFEWebGroup
System TempRXWRXWBBFEWebGroup
Program Files/Common Files/BlackbaudRXRXBBFEWebGroup
Program Files/Common Files/SystemRXRXBBFEWebGroup
The Financial Edge/SysDB folderRXRXASPNET
BBWebClient folderRXRXASPNET
FAWeb7\Downloadable Documents RXWRXWASPNET

Note: When setting advanced permissions for the Blackbaud directories, mark Replace permission entries on all child objects with entries shown here that apply to child objects. This ensures all subdirectories and files inherit the permissions.

For more information, refer to How to modify NTFS security permissions.