Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On SharePoint Server, an HTTP 403 usually means the request was understood but refused by an authorization or security policy layer—not that NTLM itself failed. NTLM negotiation problems more commonly produce HTTP 401 challenges. Identify the complete status, IIS substatus, response source, authentication zone, and authenticated identity before changing configuration.

This guide applies to SharePoint Server 2016, 2019, Subscription Edition, and similar on-premises deployments, including farms behind reverse proxies or load balancers. It does not apply to IIS administration of SharePoint Online; Microsoft hosts that service, so a 403 there is generally related to permissions, sharing, account, conditional-access, or service policy (Microsoft’s SharePoint Online 403 guidance).

What a 403 tells you

Authentication proves who made the request. Authorization decides whether that identity may access the requested URL. A successful Windows sign-in therefore does not prove that the user can open a particular site, library, item, or administrative endpoint.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Observed symptom Most likely investigation area
Repeated prompts or 401.1/401.2 IIS Windows Authentication, provider negotiation, browser trust, domain connectivity, SPN, or delegation
403 after successful Windows sign-in SharePoint permissions, IIS authorization, request filtering, SSL or client-certificate policy, or another security rule
Browser works but script fails Missing default credentials, redirects, proxy behavior, headers, cookies, or a different service identity
Only one alias fails DNS, IIS binding, host header, TLS certificate, alternate access mapping (AAM), or proxy routing
Only one site, library, or file fails Unique SharePoint permissions, item-level security, or a claims-identity mismatch
Front-end request works but a backend call fails NTLM double-hop or downstream authorization

Do not diagnose from “403” alone. IIS records the status, substatus, and Win32 status; these fields often reveal whether IIS rejected the request before SharePoint received it (IIS HTTP status-code overview).

#1 Best Overall
Sale
UGREEN Cat 8 Ethernet Cable 6FT, High Speed Braided 40Gbps 2000Mhz Network Cord Cat8 RJ45 Shielded Indoor Heavy Duty LAN Cables Compatible with Gaming PC PS5 PS4 PS3 Xbox Modem Router 6FT
  • 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
  • Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
  • Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
  • PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
  • Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5

Capture evidence before changing settings

Record the exact URL, host name, port, HTTP method, date and time, account, client type, browser result, proxy or load-balancer path, and any SharePoint correlation ID. From the IIS log, capture the status, substatus, Win32 status, username, URI, and time taken. IIS logs are normally under %SystemDrive%inetpublogsLogFiles.

Examples that change the next step include 403.1 (execute access forbidden), 403.7 (client certificate required), and 403.16 (client certificate invalid or untrusted). Other substatuses can indicate directory browsing, request filtering, IP restrictions, or policy controls. A 403 generated by a load balancer, WAF, or reverse proxy may never appear in SharePoint ULS.

1. Confirm the product and request path

Verify that the failure is in an on-premises SharePoint web application. Map the complete path:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Client to public DNS name.
  • Public name to load balancer or reverse proxy, if present.
  • Proxy to the front-end server and IIS site.
  • Front end to any downstream HTTP service.

Test DNS and TCP reachability without assuming that network access proves authentication:

Resolve-DnsName portal.example.com
Test-NetConnection portal.example.com -Port 443
whoami
whoami /groups

Compare the public URL with a direct front-end URL only as a diagnostic. A direct success does not validate the production proxy path.

2. Verify NTLM in the correct SharePoint zone

Authentication providers are configured per web application and zone. Checking only the Default zone is misleading if the failing URL belongs to Intranet, Internet, Extranet, or Custom.

Rank #2
Jadaol Cat6/Cat6A Ethernet Cable 50FT Flat with Clips 10Gbps Network, White
  • Cat 6 performance at a Cat5e price but with higher bandwidth
  • High Performance Cat6, 30 AWG, RJ45 Ethernet Patch Cable provides universal connectivity for LAN network components such as PCs,computer servers,printers,routers,switch boxes,network media players,NAS,VoIP phones
  • Jadaol cat6 standard cable support Cat8 and Cat7 network and provides performance of up to 250 MHz 10Gbps and is suitable for 10BASE-T, 100BASE-TX (Fast Ethernet), 1000BASE-T/1000BASE-TX (Gigabit Ethernet) and 10GBASE-T (10-Gigabit Ethernet)
  • UTP(Unshielded Twisted Pair) patch cable with RJ45 gold-plated Connectors and are made of 100% bare copper wire, ensure minimal noise and interference
  • The unique flat cable shape allows for a cleaner and safer installation. You can easily and seamlessly make the cable run along walls, follow edges & corners or even make it completely invisible by sliding it under a carpet.
  1. Open Central Administration.
  2. Select Application Management, then Manage web applications.
  3. Select the affected web application and choose Authentication Providers.
  4. Select the zone used by the failing URL.
  5. Under Claims Authentication Types, verify Enable Windows Authentication and Integrated Windows authentication.
  6. Select NTLM when NTLM is the intended provider, then save.
  7. Retest the exact original URL.

SharePoint supports NTLM, Classic NTLM, Negotiate, and Classic Negotiate providers. Inspect the configured provider with PowerShell:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Add-PSSnapin Microsoft.SharePoint.PowerShell

$webApp = Get-SPWebApplication "https://sharepoint.example.com"
Get-SPAuthenticationProvider -WebApplication $webApp -Zone Default

Use the actual web-application URL and zone, not a convenient but unrelated Default-zone value (Get-SPAuthenticationProvider).

3. Check IIS Windows Authentication safely

  1. Open IIS Manager, expand Sites, and select the site serving the SharePoint zone.
  2. Open Authentication and confirm Windows Authentication is enabled.
  3. Ensure Anonymous Authentication is not unintentionally granting or overriding access to a protected resource.
  4. Open Windows Authentication > Providers and confirm the intended Negotiate and/or NTLM providers.
  5. Review kernel-mode authentication and Extended Protection before changing either.

IIS Extended Protection supports Off, Accept, and Required. Accept allows clients that do not support it; Required does not (IIS Windows Authentication).

Do not treat a SharePoint-managed IIS site as an ordinary IIS application. Directly editing bindings can desynchronize IIS from SharePoint AAMs. For URL or binding changes, use SharePoint’s supported unextend/reextend process, then update AAMs and proxy configuration (Update a SharePoint web-application URL and IIS bindings).

4. Prove whether authentication completed

Browser test

Use a domain-joined client, the exact production FQDN, and a private window. Test from the same network path as the failing user. A browser success does not prove that a script sends default credentials or follows the same redirects.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PowerShell with the current identity

$response = Invoke-WebRequest `
  -Uri "https://sharepoint.example.com/sites/Test" `
  -UseDefaultCredentials `
  -Method Get `
  -ErrorAction Stop

$response.StatusCode
$response.Headers

-UseDefaultCredentials supplies the current user’s credentials after a challenge; it tests client authentication, not SharePoint authorization (Invoke-WebRequest).

Rank #3
Cable Matters 10Gbps Snagless Cat 6 Ethernet Cable, 25ft, Black
  • High-Performance Connectivity: This Cat 6 ethernet cable is designed for superior performance, with a 24 AWG copper wire core. It provides universal connectivity as an ethernet cord for LAN network components such as PCs, servers, printers, routers, and more, ensuring reliable and fast network connections
  • Advanced Cat6 Technology: Experience Cat6 performance with higher bandwidth at a Cat5e price. This network cable is future-proof, ready for 10-Gigabit Ethernet and backwards compatible with any existing Cat 5 cable network. It meets or exceeds Category 6 performance according to the TIA/EIA 568-C.2 standard
  • Reliable Wired Network Solution: Known variously as a Cat6 network cable, ethernet cable Cat 6, or Cat 6 data/LAN cable, this RJ45 cable offers a more secure and reliable connection than wireless networks. It's ideal for internet connections that demand consistency and security
  • Durable and Secure Design: The connectors of this ethernet cable feature gold-plated contacts and strain-relief boots for enhanced durability. Bare copper conductors not only improve cable performance but also comply with communication cable specifications
  • High-Speed Data Transfer: With up to 550 MHz bandwidth, this ethernet cord is ideal for server applications, cloud computing, video surveillance, and streaming high-definition video. It also supports Power over Ethernet (PoE, PoE+, PoE++) for powering devices like IP cameras, VoIP phones, and wireless access points, ensuring fast and reliable network performance.

Deliberate NTLM negotiation

curl.exe --ntlm --user "CONTOSOUserName" `
  --location --verbose `
  "https://sharepoint.example.com/sites/Test"

Use an interactive or controlled test account. Do not put a real password in shell history or a process-visible command line.

Inspect the handshake

Use browser developer tools, a network trace, or an HTTP diagnostic tool. Look for intermediate 401 responses and WWW-Authenticate: NTLM or WWW-Authenticate: Negotiate, redirects that change host names, proxy-generated responses, and the component that sends the final 403. Microsoft’s Windows Integrated Authentication diagnostics explain how to distinguish NTLM, Kerberos, and downstream failures (Windows Integrated Authentication diagnostic pages).

5. Separate SharePoint authorization from authentication

If the identity authenticated, stop repeatedly changing NTLM and inspect authorization:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Confirm membership in the intended SharePoint group.
  • Check permissions at the site, web, list, library, folder, and item levels.
  • Look for unique permissions that broke inheritance.
  • Confirm the request represents the expected Windows or claims identity.
  • Check disabled, expired, locked, or out-of-scope accounts and groups.
  • Check policies or features that restrict the requested endpoint.

In claims-based environments, a permission assigned to DOMAINuser may not match a different claims identifier representing the authenticated person. Use the identity shown by SharePoint and ULS rather than assuming the logon name is the authorization identity (Claims authentication does not validate a user).

6. Identify an IIS-generated 403

In IIS Manager, review Authorization Rules, Request Filtering, IP Address and Domain Restrictions, SSL Settings, Client Certificates, URL Rewrite, and any relevant CGI or ISAPI restrictions. A 403.14 commonly indicates directory browsing is disabled; 403.1, 403.7, and 403.16 point to the restrictions described in the status-code documentation.

If IIS records the request but SharePoint has no corresponding ULS event, investigate IIS, the proxy, WAF, certificate policy, filtering, or bindings before changing SharePoint permissions.

Rank #4
Amazon Basics RJ45 Cat 6 Ethernet Patch Internet Network Cable, 10Gbps High-Speed, 250MHz, Snagless, Gold-Plated Connectors, 15 Foot, Black
  • Cat-6 UTP (Unshield Twisted Pair) ethernet cables for connecting networked devices such as computers, printers, routers, and more
  • RJ45 connectors ensure universal connectivity; 250 MHz bandwidth
  • Low signal loss with a transmission speed up to 10 gigabit per second
  • Snagless plug design helps prevent damage when plugging/unplugging cable
  • Gold-plated contacts and bare copper conductors improve signal integrity and resist corrosion

7. Reconcile DNS, bindings, AAMs, and proxies

Compare every layer for the exact failing host:

  • DNS target and load-balancer rule.
  • IIS binding host name, port, and TLS certificate subject/SAN.
  • SharePoint public and internal URLs.
  • AAM zone assignment.
  • HTTP-to-HTTPS redirects and host-name preservation.
  • Whether the proxy preserves Windows authentication and required headers.

A typical mismatch is a user calling https://portal.example.com while the load balancer forwards to a server whose IIS binding or SharePoint AAM uses another host name. Repair the SharePoint web-application URL and AAMs through the supported SharePoint process rather than making an isolated IIS binding edit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

8. Investigate double-hop and Kerberos requirements

NTLM is connection-oriented and is not a general delegation mechanism. If the front end authenticates the user but a web part, workflow, service, or proxy must call another HTTP endpoint as that same user, the second hop may fail. Test each hop independently: client to public URL, client to front end, front end to backend, and backend to the target resource.

Where delegation is required, evaluate Kerberos with correctly registered HTTP SPNs and constrained delegation. Microsoft recommends Kerberos for Integrated Windows Authentication when its domain, DNS, service-account, and SPN requirements can be met; it is not a reason to migrate every single-hop deployment immediately (Extend claims-based web applications).

setspn -Q HTTP/portal.example.com
setspn -Q HTTP/portal

Only add or move SPNs after confirming which account owns the HTTP service. Duplicate SPNs can cause Kerberos failures and fallback (Troubleshoot Kerberos failures).

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

9. Correlate IIS logs with SharePoint ULS

Use the correlation ID shown on the SharePoint error page or response headers. SharePoint correlation IDs connect events for one request and help distinguish authorization failures from upstream denials (SharePoint ULS correlation data).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Add-PSSnapin Microsoft.SharePoint.PowerShell

Get-SPLogEvent `
  -StartTime (Get-Date).AddMinutes(-10) `
  -EndTime (Get-Date) |
  Where-Object {
    $_.Message -match "403|Forbidden|Access denied|Authentication|Authorization"
  } |
  Select-Object Timestamp, Area, Category, Level, Message

Filter a narrow time window, reproduce once, and temporarily increase authentication-related logging only when necessary. Restore normal logging afterward. A populated IIS username and a SharePoint authorization error shift attention to permissions, although they do not by themselves prove the cause. No ULS entry means the request may have been rejected upstream.

Best Value
DbillionDa Cat 8 Ethernet Cable, 6FT 40Gbps 2000MHz RJ45 LAN Cable
  • Designed for Outdoor & Direct Burial Installations – Heavy-duty double-shielded Cat8 Ethernet cable minimizes EMI/RFI interference and delivers stable long-distance performance. Waterproof, anti-corrosion PVC jacket allows safe direct burial and reliable use in outdoor or indoor environments.
  • 26AWG for Stable High-Load Networks – Thicker 26AWG conductors provide faster, more stable data transmission than standard 32AWG cables. Ideal for high-performance home networks, gaming setups, smart homes, and data-intensive applications.
  • F/FTP Shielding & Hyper-Speed Performance: Cat8 Ethernet cable constructed with 4 shielded foiled twisted pairs and 26AWG OFC conductors; supports bandwidth up to 2000 MHz and data transmission speeds up to 40 Gbps, effectively reducing signal interference and ensuring stable connections. Ideal for low-latency gaming, 4K/8K streaming, and high-speed internet connections.
  • RJ45 Connectors & Wide Compatibility: Cat8 Ethernet cable with two shielded RJ45 connectors; compatible with networking switches, IP cameras, routers, Nintendo Switch, modems, PS3, PS4, Xbox, patch panels, servers, smart TVs, and more; works with Cat7, Cat6, Cat5e, and Cat5 devices
  • Weatherproof & UV Resistant: Outdoor-rated Cat8 Ethernet cable with UV-resistant PVC jacket; withstands direct sunlight, extreme cold, humidity, and hot weather; anti-aging and durable; Includes 18-month support.

Apply the smallest fix and retest

  1. Change only the layer identified by the status, logs, and handshake evidence.
  2. Retest from the original client, URL, proxy path, and account.
  3. Test both a browser and the affected script or application.
  4. Confirm the final status and expected redirect or SharePoint page.
  5. Verify IIS and ULS entries for the repaired request.
  6. Revert temporary tracing or diagnostic security changes.

Do not make broad first-line changes such as enabling anonymous access, disabling Extended Protection, or disabling kernel-mode authentication. If a compatibility change is unavoidable, scope it narrowly, document the security trade-off, test it, and revert it when the architecture no longer requires it.

Quick decision matrix

Evidence Stop changing Next action
401 challenge or credential loop SharePoint permissions Inspect IIS providers, browser trust, domain connectivity, SPNs, and authentication settings
IIS 403 substatus, no ULS event NTLM selection Fix IIS filtering, certificates, authorization rules, bindings, proxy, or WAF policy
ULS shows access denied for the authenticated identity IIS authentication changes Repair SharePoint groups, unique permissions, or claims identity mapping
Only an alias or proxied path fails Resource permissions Compare DNS, host headers, TLS, AAMs, redirects, and authentication preservation
Front end succeeds; backend call fails Repeated NTLM toggles Design for Kerberos delegation or use an appropriate service identity

NTLM or Kerberos?

Option Strengths Limitations
NTLM Simpler single-hop deployment; no HTTP SPN registration required Poor fit for delegation and multi-hop designs; more sensitive to proxy paths and hardening changes
Kerberos/Negotiate Microsoft’s preferred Integrated Windows Authentication option when correctly configured; supports delegation Requires suitable domain, DNS, service-account, SPN, and possibly constrained-delegation configuration
Forms or federated authentication Useful for external identity providers and non-domain users Not interchangeable with Windows NTLM; Windows-negotiation clients may not work

Frequently Asked Questions

Does enabling NTLM fix a SharePoint 403?

Usually not. NTLM negotiation failures more commonly produce 401 responses. A 403 requires identifying whether IIS, SharePoint authorization, request policy, a certificate rule, or an upstream proxy refused the request.

Should Extended Protection be disabled to fix the error?

No. Investigate it only when the failure follows hardening, TLS termination, proxying, or host-name changes. Any compatibility adjustment should be narrow, temporary, tested, and reverted when possible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does the browser work while PowerShell or an application fails?

The non-browser client may omit default credentials, use another host name, mishandle redirects or cookies, traverse a different proxy, or run under an account without the required SharePoint permissions.

Can NTLM support a SharePoint backend call as the end user?

Not reliably for many double-hop designs. If a front end must delegate the user’s identity to another HTTP service, evaluate Kerberos, SPNs, and constrained delegation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.