+In an on-premise deployment scenario, if you want to allow users to navigate freely between applications, you must unselect the **Reverse rewrite host in response header** check box in IIS, under **IIS** > **Server** > **Application Request Routing** > **Proxy Settings**. If you leave this option enabled, redirects for authentication fail for users who are already logged in (have the cookie) if they navigate to one of the applications that would need to authenticate with the Provider service. This issue happens because IIS rewrites the host in the response header, resulting the in request attempting to authenticate on itself for authentication instead of the Provider service.
0 commit comments