Hi,
I was dealing with this issue for more than a month with MS support.
- Perform this command to adjust the settings below on AD FS
Get-AdfsProperties | select -expandproperty wiasupporteduseragents
Set-AdfsProperties -WIASupportedUserAgents @("MSIE 6.0", "MSIE 7.0; Windows NT", "MSIE 8.0", "MSIE 9.0", "MSIE 10.0; Windows NT 6", "Windows NT 6.3; Trident/7.0", "Windows NT 6.3; Win64; x64; Trident/7.0", "Windows NT 6.3; WOW64; Trident/7.0", "Windows NT 6.2; Trident/7.0", "Windows NT 6.2; Win64; x64; Trident/7.0", "Windows NT 6.2; WOW64; Trident/7.0", "Windows NT 6.1; Trident/7.0", "Windows NT 6.1; Win64; x64; Trident/7.0", "Windows NT 6.1; WOW64; Trident/7.0","Windows NT 10.0; WOW64; Trident/7.0", "MSIPC", "Windows Rights Management Client", "*Edg.*")
- Please follow this article to adjust the wiasupported user agents and let us know the result:
https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-ad-fs-browser-wia
- Please add the AD FS URL in the local intranet zone.
- select start > type inetcpl.cpl > enter
- select security > Local intranet > sites > advanced > enter in the AD FS address (https://sts.contoso.com) > add > close > OK > OK
4. go through this page
https://docs.microsoft.com/en-us/dynamics365/customerengagement/on-premises/deploy/post-installation-configuration-guidelines-dynamics-365#grant-application-permission-when-using-windows-server-2016-ad-fs

Also I received an advice that I should also do this(optional) except 3 mentioned above.
- On the CRM web front ends > open IIS Manager (start > run > inetmgr > enter)
- Expand server > sites > select CRM site > click on authentication in the main pane
- Select Windows authentication > advanced settings > providers
- Select the NTLM provider > remove
- Select negotiate provider > remove
5. DO NOT DISABLE integrated windows authentication (this is an error on MS page - if disabled SSO will not work)