Thank you for posting this in Microsoft Q&A.
I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others ", I'll repost your solution in case you'd like to "Accept " the answer.
Issue:
Trying to enable SSO for an IIS web server in Azure over Application Proxy and want to use Azure Active Directory (AAD) authentication with MFA, but without having to enter on-premises login credentials. We have already configured Application Proxy with SSO enabled, but it is not working as expected. We are looking for other options to enable SSO.
Solution:
Did configuration for Kerberos Constrained Delegation.
https://learn.microsoft.com/en-us/entra/identity/app-proxy/how-to-configure-sso-with-kcd
If I missed anything please let me know and I'd be happy to add it to my answer, or feel free to comment below with any additional information.
I hope this helps! Thank you again for your time and patience throughout this issue.
Thanks,
Navya.