Hi,
I'm looking to see if something should, or shouldn't be possible in relation to internal AD users being able to access Forms using SSO.
The scenario is that we (or the customer) has a Forms server that is accessible for both internal users and external participant users and is accessed via an external URL (i.e. https://cloudserver.com/forms). All of the URLs within the Forms config and LFDSSTS use this external URL.
If an internal AD user navigates to this site, they are challenged to login using a username/password or using the blue "Windows Authentication" button. If they click the blue button they are challenged to enter credentials again but these are not accepted, despite being correct (the prompt appears endlessly). If they then cancel that and enter their AD credentials in the form of DOMAIN\Username along with their password, they are able to access Forms as their AD user.
So the question is whether this should work at all, or is it the case that internal users must always enter their credentials in this way. I suspect that the browser is unable to pass through the credentials when using an external URL. Incidentally, the same behaviour is observed if we switch to an internal server name. The same behaviour is observed when accessing the external URL from the same server, or via a remote web browser where the user is logged in using a valid AD account.
Thanks,
Nigel.