API advise

Hi @johnmu,

Is this default (MS Identity) security? Adding [Authorize] attribute to the controller (or partial class) should be enough: