But there is only sign in button and when it is clicked, the windows security dialog box prompts for username and password. As part of my initial research process, I wanted to understand how a user got authenticated before getting an authentication token to access a cloud . By default, in Active Directory Federation Services (AD FS) in Windows Server, you can select Certificate Authentication (in other words, smart card-based authentication) as an extra authentication method. Configure the browser. We have enabled WIA for Intranet, set the browser user agent strings (testing with Firefox and Microsoft Chromium Edge). Enter about:config in the URL field. 3) Server-side: Check the config of SharePoint . That is why I will first show some screenshots and Configuration of my ADFS Server running on Azure VM Development Environment: Under Authentication Policies, you should enable Forms Authentication for Extranet users. Click I accept the risk!. Click Edit Primary Authentication Methods. ADFS SSO using Windows authentication. Configure Additional Authentication Methods for AD FS Optionally select Forms Authentication. Open ADFS server as an administrator. Sign in with one of these accounts UCLA HS Authentication Portal AD FS 2.0, out of the box, supports four local authentication types: Integrated Windows authentication (IWA) - can utilize Kerberos or NTLM authentication. To fix this problem, I am trying to swith the authentication type to Forms (still using the AD). Complete this task to enable Integrated Windows Authentication (IWA) on Active Directory Federation Services (ADFS) 2.0. MahmoudTolba . Then do the IIS reset after that you can able to access the IFD as shown in below screenshot. How to configure ADFS - Miro Support & Help Center Configuring single sign-on (SSO) with ADFS - IT Glue username and password box? 2 In the Actions pane , click Properties . On TeamPulse\WinLogin folder enable only Windows Authentication, and ensure that Anonymous Authentication is disabled, as represented on the image below: (Note: for TeamPulse versions up to R6 2012 the Forms Authentication also has to be enabled for the TeamPulse site and its WinLogin folder (not needed for the .