I have a simple MVC web api 2 IIS hosted application which I want to enable windows authentication (initially not using Owin). I am running this on my development machine an
If you read applicationHost.config, you will see that authentication related sections are locked down and cannot be overridden in web.config,
Thus, you need to specify that in applicationHost.config, instead of web.config. Both IIS and IIS Express have such restriction.