3 min read Sep 26, 2026

File and Folder Permissions for Uploads on Windows Hosting

Let your ASP.NET, Classic ASP or PHP site save uploaded files safely on Windows Hosting, fix Access Denied errors and stop scripts running from uploads.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

Windows servers don't use Linux-style chmod numbers like 755 or 644. Instead, each folder has an access control list (ACL) that says which Windows accounts can read or write it. Your website's code runs under its own application pool identity, and that identity needs write access wherever your site saves files.

This article shows how to save files the right way, what to do when you see “Access denied”, and how to stop an uploads folder being used to run malicious scripts.

Where to save files

FolderUse it forVisitors can download?
App_DataPrivate files: generated reports, logs, file-based databases, uploaded documents you serve through codeNo, IIS blocks it
An uploads folder in the web rootPublic files: product images, avatarsYes
binNever write hereNo

Writing any file into bin (or changing web.config) from code makes ASP.NET restart the application, which logs everyone out and slows the site.

Build paths correctly

Never hard-code a path such as C:\inetpub\wwwroot\uploads or copy one from your PC. Your site's real path on the server is different. Let the server work it out:

// ASP.NET (C#)
var folder = Server.MapPath("~/uploads");               // or HostingEnvironment.MapPath
var safeName = Guid.NewGuid().ToString("N") + Path.GetExtension(file.FileName).ToLowerInvariant();
file.SaveAs(Path.Combine(folder, safeName));
' Classic ASP (VBScript)
Dim folder
folder = Server.MapPath("/uploads")
// PHP
$folder = __DIR__ . '/uploads';

If you get “Access to the path … is denied”

  1. Check the path is inside your site. Print it temporarily (Response.Write(folder)) and make sure it is under your web root, not a folder from your development PC.
  2. Check the folder exists. Create it with FTP or File Manager first, or create it in code with Directory.CreateDirectory(folder).
  3. Check the file isn't in use or read-only. Close streams with using blocks; a file opened by one request can't be overwritten by another. Files uploaded by FTP from some tools can carry a read-only flag.
  4. Ask us to grant write access. If the path is right and the error remains, open a ticket with the exact folder path (for example /public_html/uploads) and we will check the permissions for your site.

Stop scripts running from the uploads folder

If an attacker manages to upload shell.aspx or shell.php to a public folder and then opens it in a browser, they can take over your site. Place this web.config inside the uploads folder so IIS refuses to run or serve script files there:

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
  <system.webServer>
    <security>
      <requestFiltering>
        <fileExtensions allowUnlisted="true">
          <add fileExtension=".asp" allowed="false" />
          <add fileExtension=".aspx" allowed="false" />
          <add fileExtension=".ashx" allowed="false" />
          <add fileExtension=".asmx" allowed="false" />
          <add fileExtension=".php" allowed="false" />
        </fileExtensions>
      </requestFiltering>
    </security>
    <handlers accessPolicy="Read" />
  </system.webServer>
</configuration>

Requests for those extensions now get a 404, and accessPolicy="Read" stops any handler that runs scripts. If adding the <handlers> line causes a 500.19 “locked” error, remove that line; the request filtering part still blocks the listed extensions.

Safe upload checklist

  • Allow-list extensions (for example .jpg, .png, .webp, .pdf) and reject everything else. Don't rely on the browser's content type.
  • Rename files to a random name as in the code above. This avoids overwriting, odd characters and double extensions like photo.jpg.aspx.
  • Limit the size in code and in web.config (maxRequestLength and maxAllowedContentLength; see web.config Essentials).
  • Keep private documents in App_Data and serve them through a page that checks the user is logged in.
  • Watch your disk space. Uploads count towards your plan's storage, so delete files you no longer need.

PHP and WordPress

The same rules apply. If WordPress can't upload media or install updates, it is usually because the wp-content folder isn't writable; open a ticket with the path. The web.config above works in wp-content/uploads too.

Need help?

If something doesn't work as described, open a support ticket from your client area or message us on WhatsApp at 01818160926. Tell us the folder path and the exact error, and we will check the permissions for you.

FimuroHost Team

Written by

FimuroHost Team

Technical Writer