A more maintainable approach is to use role-based authorization.

The good news is that the tools at our disposal for applying authorization rules work equally well with roles as they do for user accounts.

The default value is "/", which informs the browser to send the authentication ticket cookie to any request made to the domain. The default value is an empty string, which causes the browser to use the domain from which it was issued (such as

In this case, the cookie will not be sent when making requests to subdomains, such as admin.

It can be enabled through the Note The configuration settings listed in Table 1 specify the properties of the resulting role cache cookie.