The reason it is not supported initially is because we want to discourage developers from doing this. Regions are not associated with controllers; they are associated with routes. We wanted to deny developers an attempt to apply authorization or other security-sensitive filters for areas, since they can be circumvented.
See How to configure authorization for an entire area in ASP.NET MVC? for more information.
source share