Ensuring Successful Authentication with NTLM
Once you create the Information Lifecycle STS, it is configured to leverage Windows Authentication in IIS. If Kerberos Authentication is not enabled, many modern browsers may have an issue successfully authenticating users using NTLM, even though both providers exist in IIS configuration. To ensure successful authentication, you should disable Kerberos authentication by performing the following steps:
Open IIS
Select Records Management STS
Click Authentication Feature
Select Windows Authentication
Click the Providers… option in the pane on the right
Select the Negotiate option and click Remove
Click OK to close the Providers window