In this particular STIG it mentions several times that we need to remove the following IIS MIME type extensions: .exe; .dll; .com; .bat; .csh. What I cant find is what this will do to our SolarWinds server running OS 2020.2.5.
Because of pending inspection I went ahead and removed the extensions in IIS. SolarWinds Server/Web Page does not appear to have been affected in any way so far... Would still like to know if SolarWinds uses these extensions and if so what is the loss to SolarWinds functionality when removed.
@menningj, perhaps these two articles might shed more light if you haven't already seen them
Secure Configuration
IIS Handler Mapping
You will likely find after disabling those extensions that you can no longer download Network Atlas, the Orion Agent/ORC or the APE, AWS, HA installer from the web interface. Similarly, if you own and use the Engineers Toolset with Orion, it's possible that integration will be broken after those changes are applied.
I believe you can document the use of those files but where they are in the directory structure matters.