2FA challenge at ADFS login

Users cannot login to Zivver in Oulook with ADFS single sign-on (SSO).

The user is not automatically logged in ZIVVER in Outlook. If the user manually log is, the user gets a 2FA challenge on their Windows workspace. This also happens with a Windows and Kerberos exemption in the Zivver admin panel.

Cause

The Windows Authentication is not enabled under Intranet. To diagnose, do these steps.

  1. Go to ADFS Management Console > Service > Authentication Methods
  2. Under Primary Authentication Methods, click Edit.
Warning
Make an impact analysis before you implement a solution.

Solution 1

Add WIASupportedUserAgent as ADFS property. This makes the log in in with Windows Authentication possible. By default, it is enabled.

Solution 2

Consider to enable the Windows Authentication in the ADFS Management Console.