Troubleshooting: Microsoft Client Hangs During IWA Authentication

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: Cloud
     
     

    Overview

    Integrated Windows Authentication (IWA) lets a user on a domain-joined Windows machine authenticate with their current Windows credentials via Kerberos, without a separate username and password prompt. When a Microsoft client fails to obtain a valid Kerberos ticket during IWA, authentication can hang indefinitely on a "please wait" screen instead of falling back to a username and password prompt. This affects SecureAuth's Cloud IWA service.

    The SecureAuth login screen stuck on 'Attempting logon, please wait...' with only a Restart Login link available below it.

     

    Cause

    The affected Microsoft clients use the legacy Edge WebView browser engine, which does not fall back to a username and password prompt when the Kerberos handshake fails. You can confirm this by checking the client's user agent string for Edge/18.x

    Resolution:

    Force the workstation to use Edge WebView2 instead of the legacy Edge WebView. This requires both of the following:

    • Microsoft 365 version 16.0.13530.20424 or later.
    • Edge WebView2 installed on the workstation.

    If both conditions are met, add the following registry value on the workstation:

    1. Navigate to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\WEF.
    2. Add a new DWORD value named Win32WebView2.
    3. Set its value to 1.

    After adding this value, the Microsoft client falls back to a username and password prompt instead of hanging when Kerberos fails:

    The Office 365 login prompt reading 'Unable to retrieve SSO credentials. Please enter your username and password,' with Username and Password fields and a Submit button.

    This confirms the workstation is now falling back to Edge WebView2 instead of hanging on the hosted Edge WebView.
     
     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.