And NTLM in ASP.Net MVC

If I turn off anonymous browsing of the MVC site and only allow NTLM to authenticate user access, I assume that any page just decorated

[Authorize]

so if I only want to allow limited user access to parts of the site, will I need to add them to the AD group and use this to apply the filter?

+3
source share
1 answer

[Authorize] by default will only search for the IsAuthenticated flag. So yes, applying [Authorize] without an additional parameter, all users will be able to log in.

To limit, you can use Roles / Group (NOT OUs). It will check IsInRole (from IPrincipal).

+4
source

Source: https://habr.com/ru/post/1708200/


All Articles