I have a ASP.Net site, in which I'm trying to use Windows Authentication and Active Directory roles to limit access to some pages. I've looked at a tutorial page from Scott Gu, but I can't quite achieve what I want.

I'm ignoring the root node in my SiteMapDataSource. I want to show the "Documents" node to all users, but limit the display of the "Search" and "Upload" roles to 2 different roles. I am in the "DOMAIN\validrole" but not in the "DOMAIN\madeuprole". With the sitemap and web.config below, I am getting all the nodes displayed. If I remove the roles="*" from the "Documents" node (as suggested by Scott Gu), I get no nodes displayed.

Is there a way I can limit the display of individual child nodes without having to write custom code?

This is my sitemap:

<?xml version="1.0" encoding="utf-8" ?>
<siteMap xmlns=""&gt;
    <siteMapNode url="~/Default.aspx" 
        <siteMapNode title="Documents" roles="*">
            <siteMapNode url="~/Documents/Search.aspx" 
                         title="Search Documents" 
                         roles="DOMAIN\validrole" />
            <siteMapNode url="~/Documents/Upload.aspx" 
                         title="Upload Documents" 
                         roles="DOMAIN\madeuprole" />
            <siteMapNode url="~/Documents/Publish.aspx" 
                         title="Publish Documents" />
        <siteMapNode title="Users" roles="*">
            <siteMapNode url="~/Users/Search.aspx" 
                         title="Search Users" 
                         roles="DOMAIN\validrole" />

And this is the relevant section of my web.config:

<authentication mode="Windows"/>
    <allow roles="DOMAIN\validrole"/>
    <deny users="*"/>

<siteMap defaultProvider="XmlSiteMapProvider" enabled="true">
        <add name="XmlSiteMapProvider"
             description="Default SiteMap provider."
             securityTrimmingEnabled="true" />

Sorted - you need to set up authorization to the page in the Web.config file like this:

<location path="Documents/Upload.aspx">
            <allow roles="DOMAIN\madeuprole"/>
            <deny users="*"/>

I had tried this with the path "~/Documents/Upload.aspx", but that didn't work - it needs to be a path relative to the config file.

Also, I had to put a URL in my sitemap nodes, like this:

<siteMapNode title="Documents" roles="*" url="Made-Up.aspx">

This stopped everything disappearing, although I have no idea why. I'm not displaying the URL so any made-up one does the trick.

Graham Clark