File permissions on Windows hosting work differently from Linux. There is no chmod 755 and no owner, group and others. Windows uses access control lists (ACLs): each file and folder carries a list of accounts, and each account is allowed or denied specific rights. This guide explains the Windows model in plain terms, what you can usually change in Plesk on Domain India Windows hosting, and how to fix the common "access denied" errors in ASP.NET applications.
Your ASP.NET code runs as the identity of its IIS application pool, and it can only write where that identity has Write or Modify rights. Give write access to the few folders that need it, such as App_Data or an uploads folder, never to the whole site and never to bin. In Plesk, look for Change Permissions in the File Manager, or an additional write/modify permissions option in your domain's hosting settings. What your subscription allows varies, so if you can't find either, ask support.
1. How Windows permissions work
Every file and folder on an NTFS disk has an access control list. Each entry names an account and a set of rights, either Allow or Deny. The common rights, from least to most powerful:
| Right | What it allows |
|---|---|
| List folder contents | See which files a folder contains |
| Read | Open and read a file |
| Read & execute | Read, and run programs or scripts |
| Write | Create files and add data |
| Modify | Read, write, change and delete |
| Full control | Everything, including changing the permissions themselves |
Two rules explain most surprises:
- Inheritance. A new file takes the permissions of the folder it is created in. Set rights on a folder once, and everything placed inside follows.
- Deny wins. A Deny entry overrides an Allow for the same right. Avoid Deny entries unless you know exactly why you need one.
The Linux Owner/Group/Others model with read, write and execute bits does not apply here. Guides that tell you to set "755" or "777" on a Windows site are describing a different system.
2. Which account your code runs as
When a visitor loads a page, IIS runs your code inside an application pool, under that pool's identity. Plesk sets this up for each subscription, so the identity is a restricted account tied to your hosting, not an administrator. A separate anonymous account is used to read static files such as images and stylesheets.
What this means for you:
- Your application can read your site's files, because Plesk grants that by default.
- Your application can write only where the pool identity has Write or Modify rights.
- An error such as "Access to the path is denied" means the identity lacks a right, not that your code is wrong.
The IIS application pools guide explains pools and identities in more detail.
3. Which folders need write access
Most ASP.NET sites need write access in only a few places:
App_Data, for file-based databases, caches and application logs. IIS never serves files fromApp_Datato visitors, so it is the safest place to write.- An uploads folder, if users upload images or documents.
- A logs folder, if your app or the ASP.NET Core stdout log writes there.
- A temp or cache folder your framework or CMS uses.
Everything else, including bin, web.config and your compiled views, should stay read-only for the application.
If an attacker finds a weakness in your code, write access to bin or web.config lets them replace your application with their own. Keep them read-only for the pool identity, and never grant Full control to your application or to Everyone.
4. Changing permissions in Plesk
Plesk on Windows offers two ways to grant rights. Which of them appears depends on how your subscription is set up.
- Open Plesk.In the client area, open your hosting services, pick the Windows service and click the Plesk button.
- Open the File Manager.Go to Websites & Domains, pick your domain and open Files, then browse to the folder, for example
httpdocs\App_Data. - Look for Change Permissions.Open the folder's menu and choose Change Permissions, if it is offered. You see the accounts on the folder's list and their rights.
- Grant only what is needed.Allow Modify (or Write) on that folder for the account your application runs as. Leave inheritance on, so new files inside get the same rights.
- Save and test.Repeat the action that failed, such as an upload.
The second option is a single setting: some Plesk subscriptions show Additional write and modify permissions in the domain's hosting settings. It grants write access across the whole site at once. It is simpler, but it undoes the protection described in section 3, so use a per-folder grant where you can.
If you see neither option, your subscription doesn't allow you to change permissions yourself. Ask support, and name the exact folder and what your application needs to do there.
5. Common permission errors and fixes
| What you see | Likely cause | What to do |
|---|---|---|
| "Access to the path … is denied" | The pool identity can't write to that folder | Grant Modify on that one folder |
| HTTP 401.3 | The anonymous or pool account can't read the file | Check the file's permissions weren't removed or replaced |
| Uploads work, then fail after a deployment | Your FTP upload replaced the folder and its permissions | Re-apply the rights, or deploy without deleting that folder |
| File-based database is read-only | The database file or its folder lacks Modify | Grant Modify on the folder containing it, usually App_Data |
In the IIS access log, a request that failed on permissions often shows sc-win32-status 5, which means access denied. See checking Plesk logs for where to find it.
6. Good habits
- Keep writable folders outside public reach. Prefer
App_Data. If uploads must be public, don't allow scripts to run from the uploads folder, and check file types in your code. - Don't store secrets in writable folders. Connection strings belong in
web.configorappsettings.json, which your app reads but shouldn't write. - Check after every deployment. Deleting and re-uploading a folder can reset its permissions.
- Remove what you don't need. If you granted broad rights to debug something, take them away afterwards.
For deployment itself, see how to deploy an ASP.NET application in Plesk.
7. Where Domain India fits
Domain India Windows hosting runs ASP.NET, classic ASP and MSSQL applications under IIS, managed through Plesk. Each plan lists its sites, databases and storage, and ASP Enterprise adds a dedicated application pool. Live price below, excluding 18% GST.
- 30 GB Storage
- 150 GB Monthly Bandwidth
- 5 Websites
- 50 Email Accounts
The Plesk Windows hosting guide covers logging in, FTP, email and SSL.
How do file permissions work on Windows hosting?
Windows uses access control lists. Each file and folder lists accounts and the rights each one is allowed or denied, such as Read, Write, Modify or Full control. New files inherit the permissions of their folder. The Linux owner, group and others model, and numbers such as 755, do not apply.
Which account does my ASP.NET application run as?
It runs as the identity of its IIS application pool, a restricted account that Plesk sets up for your hosting. Your code can write only to folders where that identity has Write or Modify rights.
How do I fix "Access to the path is denied" in ASP.NET?
Grant Modify on the specific folder your application writes to, such as App_Data or an uploads folder, using Change Permissions in the Plesk File Manager if your subscription offers it. If it doesn't, ask support and name the folder.
Should I give my whole site write permission?
No. Give write access only to folders that need it. Write access to bin or web.config lets an attacker who finds a weakness in your code replace your application.
Can I change file permissions myself on Domain India Windows hosting?
It depends on your subscription. Look for Change Permissions in the Plesk File Manager, or an additional write and modify permissions option in hosting settings. If neither appears, ask support to set the permission you need.
Why did my upload folder stop working after I redeployed?
Deleting and re-uploading a folder over FTP can replace it with one that has default permissions. Re-apply the write permission, or deploy without deleting that folder.
Ready to sort out a permission error? Open My Hosting, click the Plesk button and check the folder's permissions, or open a ticket with the folder name and the exact error.
Tell us the domain, the folder and the error message, and we will help you set the right permission.
Open a ticket