IIS SSL & 2FA Setup Guide
Budget: $30 – $250 USD
I need a clear, reproducible document that walks me—or any systems admin—through configuring IIS 10 on Windows Server 2022 with a Sectigo Essential Wildcard SSL and a free 2-factor (2FA) authentication solution for console and Remote Desktop logins.
The guide must be fully illustrated with screenshots taken from an actual build so every click, dialog box, and command is obvious.
Scope of the IIS portion
• Generate a CSR in IIS 10 specifically for the wildcard (*.mydomain.com).
• Import and bind the Sectigo certificate so it secures every current and future sub-site.
• Show how to stand up an additional site/URL in HTTPS, including host headers and auto-redirect from HTTP.
• Explain how to assign the least-privileged service account that still allows the website to write a text file to a designated network share, explicitly excluding the “Everyone” group.
Scope of the 2FA portion
• Recommend a no-cost, licence-free 2FA tool that works with Windows Server 2022 logon and RDP (e.g. Duo Free, AuthLite trial, Winlogon 2FA, or another genuinely free option).
• Provide the full installation, initial configuration, and ongoing admin steps, again with screenshots.
• Include rollback instructions in case the 2FA software must be removed.
Deliverables (single consolidated document)
1. Step-by-step narrative in logical order.
2. High-resolution screenshots embedded near the relevant text.
3. Any PowerShell or batch snippets pasted as selectable text.
4. A brief test checklist I can run to confirm everything works.
Please complete the documentation within 7 days of project start; accuracy and clarity take priority over page count.
The guide must be fully illustrated with screenshots taken from an actual build so every click, dialog box, and command is obvious.
Scope of the IIS portion
• Generate a CSR in IIS 10 specifically for the wildcard (*.mydomain.com).
• Import and bind the Sectigo certificate so it secures every current and future sub-site.
• Show how to stand up an additional site/URL in HTTPS, including host headers and auto-redirect from HTTP.
• Explain how to assign the least-privileged service account that still allows the website to write a text file to a designated network share, explicitly excluding the “Everyone” group.
Scope of the 2FA portion
• Recommend a no-cost, licence-free 2FA tool that works with Windows Server 2022 logon and RDP (e.g. Duo Free, AuthLite trial, Winlogon 2FA, or another genuinely free option).
• Provide the full installation, initial configuration, and ongoing admin steps, again with screenshots.
• Include rollback instructions in case the 2FA software must be removed.
Deliverables (single consolidated document)
1. Step-by-step narrative in logical order.
2. High-resolution screenshots embedded near the relevant text.
3. Any PowerShell or batch snippets pasted as selectable text.
4. A brief test checklist I can run to confirm everything works.
Please complete the documentation within 7 days of project start; accuracy and clarity take priority over page count.