<div dir="ltr"><span style="font-size:13px">Scott, </span><div style="font-size:13px"><br></div><div style="font-size:13px">Thanks for your reply.</div><div style="font-size:13px"><br></div><div style="font-size:13px">Sorry my confusion, I'm new in Shibboleth.</div><div style="font-size:13px"><br></div><div style="font-size:13px">For what I read in the shibboleth documentation, the SPNEGO auth flow, allows to authenticate users without never type their usernames or passwords, In this particular case, the SP and idp are in a intranet, the idea is that the users only type their password in the windows login, then in theory shibboleth can validate this user with (with correct browser configuration).</div><div style="font-size:13px"><br></div><div style="font-size:13px">Am I right? Or maybe I misunderstand some part.</div><div style="font-size:13px"><br></div><div style="font-size:13px">Please let me know if this is possible to achieve.</div><div style="font-size:13px"><br></div><div style="font-size:13px">Thanks</div></div>