Add the AD FS website to the Local intranet security zone in Internet Explorer

Because the AD FS website is loaded as a FQDN, Internet Explorer places it in the Internet zone.

Add the AD FS server to the Local intranet zone in Internet Explorer

By default, Internet Explorer clients do not pass Kerberos tickets to websites in the Internet zone. You must add the AD FS website to the Intranet zone in Internet Explorer on each client computer accessing Dynamics 365 Customer Engagement (on-premises) data internally.

  1. In Internet Explorer, select Tools, and then select Internet Options.

  2. Select the Security tab, select the Local intranet zone, and then select Sites.

  3. Select Advanced.

  4. In Add this website to the zone, type the URL for your AD FS server, for example, https://sts1.contoso.com.

  5. Select Add, select Close, and then select OK.

  6. Select the Advanced tab. Scroll down and verify that under Security Enable Integrated Windows Authentication is checked.

  7. Select OK to close the Internet Options dialog box.

You will need to update the Local intranet zone on each client computer accessing Dynamics 365 Customer Engagement (on-premises) data internally.

See Also

Implement claims-based authentication: internal access