WEB API Windows身份验证配置报错及实现步骤咨询
Hey there, let's work through this Windows Authentication setup for your Web API, and fix that annoying configuration lock error you're hitting. I've dealt with this exact issue a few times, so I'll break everything down clearly.
Step 1: Configure web.config Settings
First, let's get the core config in place. You'll need to update two key sections in your web.config:
- Enable Windows Authentication and block anonymous access in the
<system.web>section:
<system.web> <authentication mode="Windows" /> <authorization> <deny users="?" /> <!-- This blocks all unauthenticated/anonymous requests --> </authorization> </system.web>
- For IIS Express or IIS 7+, you also need to configure the
<system.webServer>section to match (this is what IIS actually uses):
<system.webServer> <security> <authentication> <anonymousAuthentication enabled="false" /> <windowsAuthentication enabled="true" /> </authentication> </security> </system.webServer>
Pro tip: If you're testing with IIS Express, make sure you've enabled Windows Authentication in your project properties (right-click project → Properties → Web → Servers → Authentication).
Step 2: Code-Level Setup for Web API
Once the config is set, you can access the authenticated user's details in your controllers easily. Here's a quick example:
public IHttpActionResult GetUserInfo() { var authenticatedUser = User.Identity.Name; return Ok($"Welcome, {authenticatedUser}! You're authenticated via Windows."); }
If you're using Web API 2, double-check your WebApiConfig.cs to ensure there are no conflicting authentication filters (unless you intentionally added them).
As you suspected, this error pops up because the configuration section you're trying to modify is locked at a parent level—either the server's root applicationHost.config or a parent web.config. Here are three reliable fixes:
Option 1: Unlock via IIS Manager (Easiest for Most Cases)
- Open IIS Manager and select your server in the left Connections pane.
- Under the Management section, double-click Feature Delegation.
- Find the feature matching your locked section:
- For
<windowsAuthentication>, look for Windows Authentication - For
<anonymousAuthentication>, look for Anonymous Authentication
- For
- Change the delegation setting from Read Only to Read/Write. This updates the root config's
overrideModeDefaultto "Allow" for that section.
Option 2: Manually Edit applicationHost.config
If you have admin access to the server, you can edit the root config directly:
- Navigate to
C:\Windows\System32\inetsrv\config\applicationHost.config(you'll need to run your text editor as admin to save changes). - Find the locked section entry, e.g.:
<section name="windowsAuthentication" overrideModeDefault="Deny" />
- Change
overrideModeDefault="Deny"tooverrideModeDefault="Allow". - If the lock comes from a
<location>tag in a parentweb.config, locate that tag and either remove it or switchoverrideMode="Deny"tooverrideMode="Allow".
Option 3: Request a Per-Application Override (For Shared Hosting)
If you don't have access to the root config, ask your server admin to add a <location> tag in the parent web.config that grants your app permission to override the setting:
<location path="YourWebApiAppName" overrideMode="Allow"> <system.webServer> <security> <authentication> <windowsAuthentication enabled="true" /> </authentication> </security> </system.webServer> </location>
Final Check
After making any of these changes, restart IIS (or stop/start your IIS Express instance) and test your API again. The configuration error should be resolved, and Windows Authentication should work as expected.
内容的提问来源于stack exchange,提问作者shanthi

