How to Host a Website on Windows Server 2022 or 2025 Using IIS
Quick Answer To host a website on Windows Server, install the Web Server (IIS) role, create a website pointing to your published files, configure its permiss...
Quick Answer
To host a website on Windows Server, install the Web Server (IIS) role, create a website pointing to your published files, configure its permissions and hostname bindings, and enable HTTPS. For public access, you also need working public DNS and firewall or router rules that allow visitors to reach the server.
There is no Windows Server release named Windows Server 2021. Windows Server 2022 was released in 2021; Windows Server 2025 is the newer Long-Term Servicing Channel release. This guide covers Windows Server 2022 and 2025 with Desktop Experience. :chatgpt-content-reference{index="0"}
Before You Begin
Internet Information Services, or IIS, is Microsoft's Windows web server. The initial procedure below hosts a static website containing HTML, CSS, JavaScript, and images. Applications that run server-side code require additional components.
- A Windows Server installation with current security updates and administrator access.
- A stable server IP address, such as a static address or DHCP reservation.
- Published website files and a backup of any existing site.
- For public hosting, a domain you control, access to its DNS settings, and a reachable public endpoint.
- A TLS certificate covering your website hostname. TLS provides the encryption used by HTTPS.
- Access to Windows Firewall and any router, cloud firewall, or upstream security rules.
The local graphical instructions require Desktop Experience. Server Core can host IIS, but administration requires command-line tools or a separately configured remote management connection.
Check that your Windows Server license and hosting arrangement permit your intended use. Application compatibility, server capacity, and licensing should be assessed before production deployment.
1. Install the IIS Web Server Role
On Windows Server 2022 or 2025, open Windows PowerShell as administrator and run:
Install-WindowsFeature -Name Web-Server -IncludeManagementTools
This installs IIS and its management tools. Check that the result reports success, and restart if the installation indicates a restart is required. The management-tools parameter includes the tools available for your Windows Server installation option. :chatgpt-content-reference{index="1"}
Alternatively, use Server Manager → Manage → Add Roles and Features, select a role-based installation, choose your server, and add Web Server (IIS). Keep the default role services for a basic static website.
Open Server Manager → Tools → Internet Information Services (IIS) Manager. On a fresh installation, browsing to http://localhost should display the IIS welcome page. This verifies the default site locally, not public connectivity. :chatgpt-content-reference{index="2"}
2. Back Up Existing Configuration
If the server already hosts websites, record their bindings and application pools before making changes. In an elevated Command Prompt, create an IIS configuration backup:
%windir%\system32\inetsrv\appcmd.exe add backup BeforeBisonSite
Use a unique backup name if this name already exists. This backs up IIS configuration; separately back up website files, databases, certificates with private keys, and relevant application settings. :chatgpt-content-reference{index="3"}
3. Prepare the Website Folder
For this example, create C:\Sites\BisonSite and copy your published static website into it. This is an example location, not a required IIS directory.
Make sure the homepage is named index.html. If you are testing without an existing website, use a text editor to save a simple page with that exact filename. Check that Windows has not added a hidden .txt extension.
Keep backups, private documents, database exports, and development secrets outside the public website folder.
4. Create a Dedicated Application Pool and Website
An application pool groups IIS worker processes and provides a separate execution identity for the website.
- In IIS Manager, select Application Pools → Add Application Pool.
- Name it BisonSitePool. For this static website, select No Managed Code.
- Open its Advanced Settings and confirm that Identity is ApplicationPoolIdentity.
- Right-click Sites → Add Website.
- Enter BisonSite as the site name, select BisonSitePool, and set the physical path to C:\Sites\BisonSite.
Configure the initial binding as follows. Replace www.example.com throughout this guide with your actual hostname.
| Setting | Example value |
|---|---|
| Type | http |
| IP address | All Unassigned, or the intended local server address |
| Port | 80 |
| Host name | www.example.com |
A binding tells IIS which protocol, address, port, and hostname belong to a site. Avoid duplicate bindings. A public IP configured on a router is not necessarily an address assigned to the Windows server itself. :chatgpt-content-reference{index="4"}
On a dedicated new server, stop the unused Default Web Site. On an existing server, first confirm that nothing depends on it.
5. Configure Authentication and File Permissions
For this public static website, select BisonSite → Authentication. Enable Anonymous Authentication, select Edit, and choose Application pool identity. This makes anonymous file access use the identity that you will authorize below. :chatgpt-content-reference{index="5"}
- In File Explorer, open the properties of C:\Sites\BisonSite.
- Select Security → Edit → Add.
- Set Locations to the local server.
- Enter IIS AppPool\BisonSitePool, select Check Names, and confirm.
- Allow Read & execute, List folder contents, and Read. Apply these permissions to the website's folders and files.
The pool must exist before Windows can resolve its identity. Keep the necessary administrator and SYSTEM permissions. :chatgpt-content-reference{index="6"}
In IIS Manager, open the site's Default Document feature and confirm that index.html is listed. Keep Directory Browsing disabled.
6. Test the Correct Hostname Locally
A hostname-specific site may not appear when you browse to localhost or the server IP. IIS needs the hostname from its binding.
For temporary testing, open a text editor as administrator on your test computer and edit C:\Windows\System32\drivers\etc\hosts. Add the following example entry, replacing the address with the web server's actual LAN address:
192.168.1.50 www.example.com
When testing directly on the web server, you can use 127.0.0.1 instead if the binding accepts loopback traffic.
Browse to http://www.example.com. Your homepage should appear. Remove the temporary hosts entry when public or internal DNS is ready; otherwise, it can hide DNS mistakes during later testing.
7. Configure Network Access and DNS
Allow the Required Web Ports
Open Windows Defender Firewall with Advanced Security and inspect existing inbound rules before adding more. Where required, create a Port rule for TCP 443 and, if used, TCP 80. Apply it to the server's active network profile and choose an appropriate source-address scope.
For an intranet site, restrict access to the intended internal networks. For public hosting, allow the intended public traffic. If a reverse proxy is the only intended caller, restrict origin access to that proxy where practical. Domain policy can override locally configured firewall rules. :chatgpt-content-reference{index="7"}
| Hosting environment | Additional configuration |
|---|---|
| Server behind a router | Forward required public TCP ports to the server's stable private IP address. |
| Cloud virtual machine | Allow the required ports through the cloud network security rules as well as Windows Firewall. |
| Internal website | Use internal DNS and private routing. Public port forwarding is unnecessary. |
| Reverse proxy or load balancer | Configure its listener, backend routing, certificates, and health checks for the application. |
Cloud network rules are separate from the guest operating system's firewall. Microsoft's Windows VM quickstart illustrates opening web traffic at the cloud networking layer. :chatgpt-content-reference{index="8"}
Point the Domain to the Public Endpoint
- Create an A record for your chosen hostname pointing to the public IPv4 endpoint.
- Publish an AAAA record only if IPv6 routing, firewall access, and website service are working.
- If you also want the bare domain, such as example.com, configure its DNS, IIS binding, and certificate coverage separately.
Do not put a private LAN address in public DNS for an Internet-facing website. If your connection uses carrier-grade NAT, ordinary router port forwarding may not provide inbound access; ask the ISP about a reachable public address or use a suitable hosted endpoint.
Test public access from a different network, such as a phone using mobile data. Testing the public address from inside your own LAN can be affected by the router's support for NAT loopback.
8. Enable HTTPS
- Obtain a certificate from a certificate authority trusted by your intended visitors. Its Subject Alternative Name entries must cover every hostname you serve.
- Follow the provider's IIS enrollment or installation procedure. If you have a PFX containing the certificate and private key, use the server-level Server Certificates → Import option in IIS Manager.
- Select BisonSite → Bindings → Add.
- Choose https, port 443, and your hostname.
- For hostname-based HTTPS sharing an IP address, enable Require Server Name Indication. SNI allows the requested hostname to guide certificate selection.
- Select the appropriate certificate and save the binding.
Browse to https://www.example.com. Confirm that the expected site loads without a certificate warning. Check hostname coverage, validity dates, and the certificate chain. :chatgpt-content-reference{index="9"}
Configure certificate renewal and confirm that renewed certificates are used by the binding. Self-signed certificates are suitable for controlled testing, but ordinary public visitors will not automatically trust them.
Once HTTPS works, redirect HTTP to HTTPS through your application, reverse proxy, or an explicitly configured IIS redirection solution. Alternatively, remove the HTTP binding if HTTP access is unnecessary. Require SSL rejects HTTP requests; it does not create a redirect. Account for your certificate provider's validation method before closing port 80.
9. Add Application Components When Needed
| Website type | Additional requirements |
|---|---|
| Static HTML, CSS, and JavaScript | The static-content setup above. |
| ASP.NET Core | A compatible, supported .NET Hosting Bundle and published application output. |
| ASP.NET Framework | The required Windows ASP.NET role services and application-compatible framework configuration. |
| PHP or WordPress | A supported PHP runtime, IIS FastCGI configuration, required extensions, and the application's database dependencies. |
| Node.js or Python application | An application-specific runtime and supported deployment architecture, potentially with IIS acting as a reverse proxy. |
For ASP.NET Core, install IIS before the Hosting Bundle. If the bundle was installed first, repair it afterward. Deploy the application's publish output, including its generated web.config, and use the documented IIS settings for that application. Installing the .NET SDK alone does not replace the IIS hosting components. :chatgpt-content-reference{index="10"}
Verify the Deployment
From another Windows computer, run this read-only check in PowerShell; administrator privileges are not normally required:
Test-NetConnection -ComputerName www.example.com -Port 443
TcpTestSucceeded: True confirms a TCP connection to port 443. It does not verify certificate trust or application correctness. If false, check name resolution, routing, firewall rules, forwarding, and the HTTPS listener. :chatgpt-content-reference{index="11"}
- Confirm that the expected homepage and static assets load over HTTPS.
- Test important application functions, including authentication and forms where applicable.
- Check HTTP redirection if configured.
- Confirm that private files and directory listings are not exposed.
- Remove temporary hosts entries and repeat testing through DNS.
- Check operation after a planned server restart.
Troubleshoot Common Problems
| Symptom | What to check |
|---|---|
| IIS welcome page or wrong website | Requested hostname, DNS, and conflicting site bindings. |
| Works locally but not externally | Windows and upstream firewalls, public endpoint, NAT forwarding, and ISP restrictions. |
| 401.3 | File permissions for the effective authentication identity. |
| 403.14 | Missing default document with directory browsing disabled. Verify index.html and Default Document settings. |
| 404 | Requested path, deployed files, application routing, and the detailed IIS substatus. |
| 500.19 | Invalid or inaccessible configuration; inspect the detailed error and configuration location. |
| 503 | Application pool state, startup failures, rapid-fail protection, and server logs. |
| HTTPS warning | Certificate hostname, expiry, chain, and selected binding. |
IIS status and substatus codes help distinguish causes; the visible browser message alone may be insufficient. In IIS Manager, check the site's Logging settings for its log location. Also inspect Event Viewer → Windows Logs → Application for relevant failures. Keep detailed diagnostics restricted to administrators. :chatgpt-content-reference{index="12"}
Rollback and Maintenance
For an unsuccessful new deployment, stop the new site and reverse only the bindings, firewall rules, DNS records, and permissions you added. Restore previous website files if you replaced them.
To restore the earlier configuration backup, run this in an elevated Command Prompt:
%windir%\system32\inetsrv\appcmd.exe restore backup BeforeBisonSite
This does not restore website content, databases, DNS, or firewall settings. Recheck every affected website afterward. :chatgpt-content-reference{index="13"}
For ongoing operation, monitor availability, disk space, certificate expiry, and application errors. Maintain tested backups and apply Windows, application, and runtime updates through a planned maintenance process.
Frequently Asked Questions
Can I host several websites on one server?
Yes. Use distinct bindings and separate application pools. For HTTPS sites sharing an IP address, configure SNI and certificates covering each hostname.
Do I need to install a DNS server on the web server?
No. Your domain's DNS provider can manage public records. IIS hosting and DNS hosting are separate services.
Does installing IIS also install a database or email server?
No. Databases and email are separate services. Add them only when the application requires them, using their own supported deployment procedures.
Can an internal website use HTTPS?
Yes. Use a hostname and certificate trusted by the intended client devices. An organizational certificate authority can be appropriate when its trust is managed on those devices.
Does this setup provide high availability?
No. A single server remains a single point of failure. High availability requires additional design for application instances, traffic distribution, certificates, and shared or replicated data.
Sources
- Microsoft: Windows Server Release Information
- Microsoft: Install-WindowsFeature
- Microsoft: Build a Static Website on IIS
- Microsoft: Application Pool Identities
- Microsoft: Anonymous Authentication
- Microsoft: IIS Bindings
- Microsoft: Set Up SSL on IIS
- Microsoft: Configure Windows Firewall Rules
- Microsoft: Create a Windows Virtual Machine and Allow Web Traffic
- Microsoft: Host ASP.NET Core on Windows with IIS
- Microsoft: Test-NetConnection
- Microsoft: IIS HTTP Status Codes
- Microsoft: AppCmd Configuration Backup and Restore
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.