<location path="admin"> <system.web> <authorization> <allow users="..." /> <deny users="*" /> </authorization> </system.web> </location>