Asp.net core Windows authentication only for specific users

Viewed 1873

I have a web application protected by windows authentication. In Asp.NET 4.5 I can use the web.config file to specify exactly which users can use it

<configuration>
    <system.web>
        <authorization>
            <allow users="TEST\admin" />
            <deny users="*" />
        </authorization>
    </system.web>
</configuration>

In Asp.NET core the web.config file is gone, I guess the allow and deny rules should be moved to launchSettings.json file, but I can't find any reference on how to do it. So... How can I do it? This is the current authentication setting

"iisSettings": {
    "windowsAuthentication": true,
    "anonymousAuthentication": false,
}
1 Answers

Actually launchSettings.json file is only used by VS. When you publish your app (or run without VS) launchSettings.json is not being used. When you run with IIS/IISExpress you just need to make sure that your web.config has correct settings.

See this Asp.Net core MVC application Windows Authentication in IIS

Related