Some HRPro functions require additional access to files, folders, or scheduled tasks. These may include database backup downloads, restore uploads, configuration updates, and Business Alert scheduling.
Certain functions in HRPro require Advanced Access Rights for the Internet Information Server (IIS). These include:
Enabling Business Alert to work with Windows Task Manager to schedule tasks.
Activating the Download button in Database Backup.
Enabling the Upload and Restore button in Database Restore.
Modifying HRPro.config when enabling SQL Server Password Encryption.
Reading files from the hard disk.
Open IIS Manager.
Under Sites, select the HR Workspace application.
Click Basic Settings and note the application pool name.
Select Application Pools, select that pool, and click Advanced Settings.
Confirm that Identity is set to ApplicationPoolIdentity.
The Windows account for the pool is:
IIS AppPool\<ApplicationPoolName>
For example:
IIS AppPool\HRWorkspacePool
IIS allows you to grant folder permissions directly to this account.
Grant access only to the location used by the relevant function:
Backup downloads: Grant Read on the folder containing the backup files.
Restore uploads: Grant Write on the upload folder. Grant Modify only if HRPro must also replace or delete files.
Other file operations: Grant Read for viewing files, or Modify where creating, updating, and deleting files is required.
Configuration updates: If a function needs to update HRPro.config, grant the necessary write access for that operation, then restore read-only access if ongoing write access is not required.
Do not grant Modify or Full control to the entire application folder as a general workaround. Use permissions limited to the affected files or folders.
Right-click the required folder and select Properties.
Open Security > Edit > Add.
Under Locations, select the local server.
Enter IIS AppPool\<ApplicationPoolName>.
Click Check Names, then OK.
Select the required permissions and apply the changes.
Test the affected HRPro function.
For database backup and restore operations, IIS and SQL Server need separate permissions.
The IIS account handles web uploads and downloads. The SQL Server service account needs access to the backup files used by the database engine. The SQL login must also have the required backup or restore permissions.
If a backup or restore fails, check which account and operation caused the error before changing permissions.
Business Alert uses Windows Task Scheduler. Use a dedicated Windows account with permission to create, update, and run Business Alert tasks. Configure the HR Workspace application pool and Business Alert to use this account, and grant it Log on as a batch job rights.
Do not use LocalSystem or an administrator account as a general fix for permission errors. These accounts grant excessive privileges. For temporary troubleshooting in a controlled test environment, you may use LocalSystem to check whether an issue is permission-related. Restore ApplicationPoolIdentity after testing and grant only the permissions required. Do not leave this setting enabled in production.
To temporarily change the application pool identity:
Open Internet Information Services (IIS) Manager
Select the HRPro Website for which you need to modify permissions
Go to Basic Settings and see which application pool you're using. Usually, it is named DefaultAppPool
Go to Application Pools and find the application pool from #3
Right-click the application pool and select Advanced Settings...
Change the Identity from ApplicationPoolIdentity to LocalSystem.
Click OK to save, then test the affected function.
After testing, restore the identity to ApplicationPoolIdentity.