To encrypt the contents of web.config:

  1. Start an administrative command prompt.
  2. Navigate to Windows\Microsoft.NET\Framework\<version> folder and locate apsnet_regiis.exe. 
  3. Run the following 2 commands to encrypt the database connection string and application settings. These must be run separately as you can only encrypt one section at a time. In this case, the commands assume the site name is "" and the application is called "mds"
    1. .\aspnet_regiis.exe -pe "connectionStrings" -site -app "/mds"
    2. .\aspnet_regiis.exe -pe "appSettings" -site -app "/mds"

NOTE: If you need to edit these sections change "-pe" in the above commands to "-pd" and re-run them.  After your edits have been made, run them again with "-pe"