# Make the MDM Service Work Together with IIS

> Run the MDM service and an IIS website, such as the WebConsole, on the same server so that both share port 443.

Source: https://docs.capaone.com/capainstaller/installation-and-maintenance/getting-started-with-device-management/mobile-device-management-implementation-plan/make-the-mdm-service-work-together-with-iis/  
Product: CapaInstaller — a separate CapaSystems product; do not apply this page to any other.

Use this page to run the CapaInstaller MDM service on the same server as Internet Information Services (IIS), for example a server that also hosts the WebConsole.

The MDM service requires SSL, which means port 443. If an IIS website on the server already uses port 443, the MDM service and the website must share the port. IIS itself can host several websites on the same port.

## Plan the host names

Give each service its own subdomain, and use a wildcard SSL certificate such as `*.company.com`. A certificate issued to a single host name can't cover both subdomains.

| Service | URL | Subdomain |
|:--------|:----|:----------|
| WebConsole | `https://tstdmz01.company.com/WebConsole` | `tstdmz01` |
| MDM service | `https://mdm.company.com/cimdm` | `mdm` |

## Add a host name to the IIS binding

By default, IIS takes full control of the port assigned to a website. To share the port, narrow the website's binding to one host name.

1. Stop the MDM service.
2. Open **Internet Information Services (IIS) Manager**.
3. In the **Connections** pane, expand the server and **Sites**, and then select the website — for example, the one that hosts the WebConsole.
4. In the **Actions** pane, select **Bindings**.

   <!-- SCREENSHOT: IIS Manager with the website selected under Sites and Bindings highlighted in the Actions pane. Crop to the two panes. -->
5. Select the `https` binding on port 443, and then select **Edit**.
6. In **Host name**, enter the website's host name without the scheme and port, for example `tstdmz01.company.com`. Select **OK**.

   <!-- SCREENSHOT: Edit Site Binding dialog with the Host name field filled in. Crop to the dialog. -->

   The binding now filters on the host name, so the website only handles requests for that host name.
7. Restart the MDM service.

The WebConsole now opens at `https://tstdmz01.company.com/WebConsole`, and the MDM service at `https://mdm.company.com/cimdm`.
