Microsoft updated its IIS Lockdown Wizard for IIS 4.0 and IIS 5.0 last month. The 2.1 release now includes profiles for various server configurations such as a Microsoft Exchange Server or a FrontPage-enabled Web server, so that the tool can leave enabled the IIS features necessary for these server applications to work.
IIS Lockdown Wizard 2.1 also automatically installs Microsofts formerly separate URL Scan tool to provide a single install for both of Microsofts IIS security add-ons. I strongly recommend running it because the Lockdown Wizard does an excellent job of hardening IIS. It can be downloaded from www.microsoft.com/technet/security/tools/locktool.asp.