On Windows Server the web server is IIS (Internet Information Services). You install it as a server role, create a site pointing at a folder with your files, bind a name (the domain) and a port to it, and open port 80 in the Windows firewall. This article is for a Windows Server VPS where you have the administrator access (connecting to a Windows VPS with Remote Desktop); what runs inside is yours, and our support does not install or repair IIS (how far our support goes).
Step by step
| 1 |
Install the role. In Server Manager, Manage, Add Roles and Features, and tick Web Server (IIS). Or, in a PowerShell window as administrator: Install-WindowsFeature -Name Web-Server -IncludeManagementTools. Afterwards the server’s address in a browser, from inside the server, should show IIS’s welcome page.
|
|
| 2 |
Put the site in a folder. For example C:\sites\yourdomain.tld with a test index.html. Avoid C:\inetpub\wwwroot for real sites.
|
|
| 3 |
Open IIS Manager (Internet Information Services (IIS) Manager, or inetmgr in the Run box). Under Sites, right-click, Add Website.
|
|
| 4 |
Fill in the site: the Site name, the Physical path (the folder), and the Binding: type http, the IP (or “All Unassigned”), port 80 and the Host name with your domain. The name is what allows several sites on one IP.
|
|
| 5 |
Settle the clash with the default site. Default Web Site also listens on 80 with no name. Stop it (right-click, Manage Website, Stop) or give it another name or port, so it does not answer in place of yours.
|
|
| 6 |
Give read access to the site’s identity. Each site runs in an application pool whose identity is IIS AppPool\PoolName. The folder must let it read; for example, from an administrator command line: icacls "C:\sites\yourdomain.tld" /grant "IIS AppPool\yourdomain.tld:(OI)(CI)RX".
|
|
| 7 |
Open the port in the Windows firewall. In Windows Defender Firewall with Advanced Security, check that the inbound rules for web traffic (HTTP, port 80, and HTTPS, port 443) are enabled. Then point the domain at the VPS IP (pointing a domain at your own VPS).
|
|
HTTPS on IIS
Import the certificate into Windows, and on the site go to Bindings, Add, type https, port 443, pick the certificate and tick Require Server Name Indication if you have more than one site on the IP. For free certificates there are ACME clients for Windows, third-party and open source; they are yours, and so is the renewal. Typical failures: no padlock on your site.
The errors you will meet
| What shows |
Usual cause |
| 403.14 Forbidden |
The folder has no default page (for example index.html) and directory browsing is off. Create the file, or add it under Default Document. |
| 401 / 403.3 (permissions) |
The pool’s identity cannot read the folder. Go back to the permissions step. |
| 500.19 |
A configuration error: a web.config with bad syntax, or a rule that needs a module that is not installed (for example URL Rewrite). |
| 503 Service Unavailable |
The application pool is stopped or fails to start. Look under Application Pools and start it; Event Viewer says why. |
| The site opens inside the server but not from outside |
The Windows firewall, the domain’s address or the Binding. See ports and firewall. |
|
A Windows Server exposed to the internet is attacked every day. Keep Windows Update on, use a strong administrator password and restrict remote access: making Remote Desktop safer. If your site needs PHP, databases or other technologies, check that Windows is really what you want: Linux or Windows.
|
|
IIS logs go, by default, to C:\inetpub\logs\LogFiles, and system errors to Event Viewer. When something fails, the reason is there. A VPS’s backups are not included by default: backing up a VPS.
|
|
Lost access to the Windows server? The panel console gets in without the network: tell us the service name.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon) See plans |