Hi @Piyush Meshram ,
TLS(MTLS) and Authentication are not same thing. TLS occurs in the process of establishing a connection between the client and the server. Because before the connection is established, the two will exchange data and keys with each other. Then calculate to determine whether the other party is safe. This process is called a TLS handshake.
The Authentication in IIS, such as anonymous authentication, Windows authentication. All are based on successfully establishing a connection between the client and the server, and then verify the user's identity. Not the client.
So if the client cannot provide a certificate, it cannot establish a connection with the server during the TLS handshake.
- The client device cannot connect to the server, and the user cannot access the sites.
- Similarly, IIS's denial and permission of IP also need to be based on the connection.
If the answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
Best regards,
Bruce Zhang