Version Affected: Cloud
Overview
Integrated Windows Authentication (IWA) lets a user on a domain-joined Windows machine authenticate with their current Windows credentials via Kerberos, without a separate username and password prompt. When a Microsoft client fails to obtain a valid Kerberos ticket during IWA, authentication can hang indefinitely on a "please wait" screen instead of falling back to a username and password prompt. This affects SecureAuth's Cloud IWA service.
Cause
The affected Microsoft clients use the legacy Edge WebView browser engine, which does not fall back to a username and password prompt when the Kerberos handshake fails. You can confirm this by checking the client's user agent string for Edge/18.x.
Resolution:
Force the workstation to use Edge WebView2 instead of the legacy Edge WebView. This requires both of the following:
- Microsoft 365 version 16.0.13530.20424 or later.
- Edge WebView2 installed on the workstation.
If both conditions are met, add the following registry value on the workstation:
- Navigate to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\WEF.
- Add a new DWORD value named Win32WebView2.
- Set its value to 1.
After adding this value, the Microsoft client falls back to a username and password prompt instead of hanging when Kerberos fails:
This confirms the workstation is now falling back to Edge WebView2 instead of hanging on the hosted Edge WebView.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.