Typically, the user rights assigned to the IIS_WPG group is sufficient for most Web sites or applications. However, when a Web site or application requires additional user rights to run properly, you must assign the required rights to the service account that is used as the identity for the Web sites and applications.
You grant user rights based on where the account is stored. If the service account is created locally on the Web server, you make changes in user rights through Local Computer Policy by using the Group Policy Object Editor MMC snap-in. When the service account is created in Active Directory, make the changes on the appropriate Group Policy object in Active Directory.
Credentials: Membership ...