<div dir="ltr">Hello all,<div><br></div><div>I have deployed Shibboleth SP v3.0.3, on Windows platform, protecting my Web Application hosted on IIS. The IdP is an Active Directory(AD) with ADFS with SAML 2.0 enabled. Relying party registration has been done properly within the IdP.</div><div><br></div><div>Users of my application use Windows desktop and they login to their local desktop using credentials belonging to the same AD domain that is configured as IdP for my Web Application. When the user navigates to my application URL, the browser properly redirects to IdP and is presented with a username and password screen. Upon entering the correct credential, the user is redirected back to my application and login successfully.</div><div><br></div><div>However, my customer/user is expecting this to work such that the user should not be prompted for the credential at IdP once again and instead automatic authentication should happen based on the account the user is logged on to the local machine. Users' expectation is that Windows credentials used for local desktop should be forwarded to SP and IdP and an automatic login should happen to the application.</div><div><br></div><div>It is a reasonable ask from the customer. But I am unable to understand how to configure Shibboleth SP to enable this authentication flow. Any help or pointers, based on your experience, would be of great help.</div><div><br></div><div>Thank you for reading through this email.</div><div><br></div><div>Regards</div><div>Prashanth</div><div><br></div></div>