August Meetup - Roland Guijt - Authentication and Authorisation in ASP.NET Core

This is a past event

37 people went

Madgex Ltd

1 Gloucester Place · Brighton

How to find us

We are on the first floor. When you arrive there should be a Madgex stall member in the building foyer to greet you. If no one is there, please use the door entry buzzer outside.

Location image of event venue


Please arrive between 6:00pm and 6:25pm. Talks will start at 6:30pm. Once the talks are underway we may not be able to guarantee access.

Authentication and Authorisation in ASP.NET Core


With all the authentication and authorisation options in ASP.NET we had in the past it's hard to determine how to secure your app nowadays. On top of that Microsoft completely re-did a large part of the security features in ASP.NET Core.

ASP.NET Identity enables you to do authentication for a single application and has a lot of ready-to-go features, but isn't it better to do centralized authentication with a token service using OpenId Connect? We'll explore that question and I'll explain and show you both ASP.NET Core identity, cloud options and the IdentityServer framework that helps you write a token service.
Authorisation has undergone a complete overhaul in ASP.NET Core. There's still the authorize attribute, but the recommended way of using it is by utilizing policies. You'll see how that works as well.

After this session you'll know what options you have for implementing authentication in ASP.NET Core. And you will understand how to implement these options. Also you'll know how to enforce authorisation rules in your ASP.NET Core app.

About Roland:

I'm a Microsoft MVP with the Visual Studio Development Technologies expertise. Professional senior software developer, architect and trainer for more than 17 years. I'm also a Pluralsight author.. Having experience in all .Net type of applications, most of my current projects are web apps in MVC with HTML5. And with that, I learned many client-side Javascript frameworks and libraries such as Angular, React and Knockout. Most of the web projects I worked on are deployed in the Azure cloud.

I'm an international speaker. Conferences include DevConnections (Las Vegas) and TechDays in The Netherlands.

The last 8 years I'm also a Microsoft Certified Trainer (MCT). I led a lot of Microsoft courses using the Microsoft Official Curriculum (MOC), almost all the software development courses available from Microsoft as well as custom courses.