In authorization filter I can set result to either Forbidden or Challenge. Constructors of both have an overload accepting authentication scheme na
Forbidden
Challenge