How to make single sign on work for both internal and external usersIssue If you have a requirement to make Single Sign On work for internal users within your network and users accessing the instance externally from outside of your network, you need to ensure below configurations are in place on the identity provider record. Create AuthnContextClass check box field on identity provider record should be unchecked. AuthnContextClassRef Method field should have a value of urn:federation:authentication:windowsReleaseAll releases