User login in asp.net MVC using windows authentication without prompt

Viewed 1208

We want to host ASP.NET MVC 5 project (.NET 4.8 Framework) where users will be automatically authenticated via their Windows login. When the users call the hosted project via the browser, then the browser should not prompt the user to login. The browser should pass the login-data to the server-side controller automatically.

Regarding this article, the Integrated Windows Authentication uses the security features of Windows clients and servers. Unlike Basic or Digest authentication, initially, it does not prompt users for a user name and password.

So the Integrated Windows Authentication seem to be the correct solution for our problem.

The MVC 5 Project has the following entry in the web.config file:

<configuration>
  [...]
  <system.web>
    [...]
    <authentication mode="Windows" />
    <authorization>
      <deny users="?" />
    </authorization>
  </system.web>

Here are the authenciation settings in IIS:

authentication settings iis - Windows Authentication

The authenticated user data is accessible in the controller by the following code:

public class HomeController : Controller
{
    public ActionResult Index()
    {
        var lWindowsIdentity = Request.LogonUserIdentity;

        [...]
    }
}

The Problem: When we access the site in the browser via the binding http://192.168.178.41 then we expect, that the user is logged in automatically, but an prompt appears:

enter image description here

How to login in asp.net MVC using windows authentication without prompt?

4 Answers

Check if the page is in the intranet zone... if not you might need to add it specifically to the intranet zone using the servername and/or ip address via configuration / internet options / security / local intranet / websites

Disable "Anonymous authentication" and make sure that "NTLM" is above "Negotiate" as a windows authentication provider (right-click in IIS on "Windows Authentication")

And since you disabled the "anonymous authentication" provider, there is no need for the <authorization> section in your web.config. remove it.

Finally test if it works.

I think on development web server that is with in the localhost environment it will skip the prompt but when the application runs through IIS(production) server, it prompts the user with the dialog that is pretty normal behavior. When you initiate a local url(your local ip) it kicks in IIS web server(not local) which checks for windows authentication and issues a prompt.

Please see this

Related