[Authorize] by default will only search for the IsAuthenticated flag. So yes, applying [Authorize] without an additional parameter, all users will be able to log in.
To limit, you can use Roles / Group (NOT OUs). It will check IsInRole (from IPrincipal).
source
share