Hello,
The 403 should be addressed by allowing anonymous access only to the ACME challenge path rather than weakening security for the entire site. Create /.well-known/acme-challenge/ and add a web.config there:
<configuration>
<system.webServer>
<security>
<authorization>
<clear />
<add accessType="Allow" users="*" />
</authorization>
</security>
</system.webServer>
</configuration>
Also verify IIS Request Filtering has not blocked .well-known or acme-challenge as a hidden segment or URL sequence. Do not disable Request Filtering or authentication globally. Test http://yourdomain/.well-known/acme-challenge/<token> and confirm IIS returns 200.
If it still returns 403, check the IIS log for sc-substatus and sc-win32-status; these will identify the specific authorization or IIS module causing the denial.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
DV.