I would definitely go for external authorization. This does not mean that it will be slower. This means that you have purely divided access control from business logic.
An XACML overview is a good way to go. TC is very active, and active companies such as Boeing, EMC, Veteran Administration, Oracle and Axiomatics are active participants.
The XACML architecture ensures that you can get the performance you need. Because enforcement (PEP) and decision making (PDP) are loosely coupled, you can choose how they communicate, which protocol they use, use multiple decisions, etc. This means that you have the choice to integrate according to your performance needs.
There is also a standard PDP interface defined in the SAML profile for XACML. This guarantees you "control of the future" if you are not blocked by any specific solution for suppliers.
Access Control for webapps You can simply go to PEP for .Net webapps using HTTP filters in ISAPI and ASP.NET. Axiomatics has one ready-made option for this.
Ongoing implementations If you check the Axiomatics customer page, you will see that they have Paypal, Bell Helicopter and more. Thus, XACML is indeed a reality, and it can solve very large deployments (hundreds of millions of users).
In addition, Datev eG, a leading financial services provider, uses the Axiomatics.Net PDP implementation for its services / applications. Since .Net PDP is implemented in this case, performance is optimal.
Otherwise, you can always choose from ready-made PEPs for .Net that integration with any PDP is, for example, SOAP-based XACML authorization service.
High performance with XACML In July last year, at the Gartner Catalyst conference, Axiomatics announced the launch of its latest product, Axiomatics Reverse Query, which will help you deal with the "billion records" problem. It is intended for access control for data sources, as well as for the RIA. It uses a pure XACML solution so that it remains compatible with other solutions.
In fact, Kuppinger Cole will soon host a webinar on this topic: http://www.kuppingercole.com/events/n10058
Check out the Axiomatics ARQ press release here: http://www.axiomatics.com/latest-news/216-axiomatics-releases-new-reverse-query-authorization-product-a-breakthrough-innovation-for-authorization-services .html