# Endpoint Access Control

**URL:** <https://forums.losant.com/t/endpoint-access-control/1595>\
**Category:** Bug Report\
**Tags:** experience\
**Created:** [March 7, 2019, 9:32pm UTC](https://forums.losant.com/t/endpoint-access-control/1595 "2019-03-07T21:32:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Armitage](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.losant.com/david_armitage/32/1060_2.png) [@David\_Armitage](https://forums.losant.com/u/David_Armitage)\
**Post date:** [March 7, 2019, 9:32pm UTC](https://forums.losant.com/t/endpoint-access-control/1595/1 "2019-03-07T21:32:57Z")

</div>

I have set up an Endpoint and Access Control seems to be having no effect. No matter which setting I pick I can still get to the page. This endpoint is simple, connecting directly to an Experience page. I have tried browsing using an Incognito Window to ensure that it was not picking up a valid token, to no avail.

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![JuliaKempf](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.losant.com/juliakempf/32/2446_2.png) [@JuliaKempf](https://forums.losant.com/u/JuliaKempf)\
**Post date:** [March 7, 2019, 9:58pm UTC](https://forums.losant.com/t/endpoint-access-control/1595/2 "2019-03-07T21:58:28Z")

</div>

Hello @David_Armitage!

This can occur if you have set your “Unauthorized Reply Type” to also route to the same Experience page. The “No Static Reply” or “Redirect” options will ensure an unauthorized user cannot access the page.

Hopefully this helps!  
Julia

---

<div class="post-metadata">

**Author:** ![David\_Armitage](https://sea1.discourse-cdn.com/flex015/user_avatar/forums.losant.com/david_armitage/32/1060_2.png) [@David\_Armitage](https://forums.losant.com/u/David_Armitage)\
**Post date:** [March 7, 2019, 10:26pm UTC](https://forums.losant.com/t/endpoint-access-control/1595/3 "2019-03-07T22:26:26Z")

</div>

Yes…user error! I had them switched. I was anticipating that the UI would offer the Success option first (ie., authenticated user). Instead it sets the unauthorized first. Not what I was expecting. I should have read the UI more carefully. Thank you for getting back to me quickly.
