Good day,

For sake of argument, assume that someone has set up a MS Active Directory domain with Kerberos disabled, but NTLM still enabled.  In that situation, would a user browsing to a Keycloak-protected application, with LDAP+SPNEGO enabled (against that MS AD system) still allow for Integrated Windows Authentication (auto-login without prompt) to web application?

Thanks much,
Guy

<re-sending today as same message yesterday didn't make it through to the list>