Support Request: Hybrid IAM Authentication (AD & Microsoft Entra) in IIS

Shri Krishna Ulithaya 0 Reputation points
2025-02-25T03:31:13.2033333+00:00

Dear Microsoft Support,

We have an on-premises application that currently uses Active Directory (AD) as both a resource and Identity and Access Management (IAM) system. The application supports both Windows Authentication and Single Sign-On (SSO).

We are now integrating Microsoft Entra ID as an additional IAM solution. Our current configuration is as follows:

  • If AD is the IAM provider, users authenticate via Windows Authentication.
  • If Microsoft Entra ID is the IAM provider, users authenticate via SSO.
  • Authentication settings in IIS are configured accordingly.

Now, we aim to support a hybrid IAM model, where authentication is dynamically determined based on the user or device:

  • Users from AD should log in using Windows Authentication.
  • Users from Microsoft Entra ID should log in using SSO.

However, we are facing challenges in logging in after configuring IIS with both Windows Authentication and Anonymous Authentication. We need guidance from Microsoft on how to properly configure IIS and handle authentication dynamically for both IAM systems.

Could you please assist us in resolving this issue ?

Best regards,
Shri Krishna
Flexera Software

Windows Server Identity and access Active Directory
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.