In some places, a security scan is the rule and any deviation must be justified. I'm dealing with the same issue right now where I need to get rid of the IISADPWD directory. This is a couple of months after the fact, but, one option given is to ensure that the virtual directory is not present on any sites then lock down the folder. If you're using the same security scanner that I have, your report will list this as a workaround with justification that you can provide the accreditation team.