Authentication answers who is calling. Authorization answers what they are allowed to do. They get discussed together and they fail separately, which is why they have separate sections below.

ASP.NET Core Identity handles the first one for you: users, passwords, lockout, confirmation emails, two-factor. Most of what follows is either configuring it, replacing a piece of it, or connecting it to something external like Duende, Auth0 or Azure AD.

The last few sections are not framework features at all. They cover the mistakes that get made anyway: weak password storage, a missing CORS rule, the OWASP risks that keep turning up in real breaches.

ASP.NET Core Identity

The built-in user store, and the parts of it you will end up changing.

JWT, Tokens and Refresh Tokens

Stateless authentication and the token lifecycle that comes with it.

OAuth, OpenID Connect and External Providers

Letting somebody else own the login, and the flows you have to pick between when you do.

Authorization

Policies, claims and roles. Most authorization bugs are a claim that was never issued rather than a policy that was wrong.

API Security: Keys, CORS and Headers

Guarding an API rather than a browser session.

Cryptography and Password Storage

Hashing, salting and the .NET APIs that do it properly so you do not have to invent anything.

The OWASP Top 10

The failures that keep appearing in real breaches, each with what it looks like in .NET code.

Where to Go Next

Identity is rarely the whole job. These are the pages next to it:

Test the failure path. An authorization rule that has only ever been exercised by a user who passes it has not been tested at all.