Enabling Integrated Windows Authentication in Internet Explorer

Follow these steps to ensure that Internet Explorer users can use Integrated Windows Authentication (IWA) to authenticate through ADFS. The steps might vary slightly based on Internet Explorer version.

Procedure

  1. Start the browser and open Internet options.
  2. Click the Advanced tab. In the Security section, select Enable Integrated Windows Authentication.
  3. Click the Security tab, select Local intranet and complete the following steps:
    1. Click Custom level. In the User Authentication section, select Automatic logon only in Intranet zone and then click OK.
    2. Click Sites and select all of the following settings:
      • Include all local (intranet) sites not listed in other zones
      • Include all sites that bypass the proxy server
      • Include all network paths (UNCs)
    3. Click Advanced. In the Websites box, add the URL to the full SPN account that you created in ADFS. Use HTTPS, for example: https://adfs01.us.renovations.com. Click OK.
    4. Click OK twice to close Internet options.