The firewall-published configuration uses a firewall device, such as Microsoft Threat Management Gateway (TMG), to reverse proxy the AD FS Federation Service directly to the Internet. For more information about how to configure AD FS in a firewall-published configuration, click the following article number to view the Microsoft Knowledge Base article:
2510193�Supported scenarios for using AD FS to set up single sign-on in Office 365, Windows Azure, or Windows Intune
Additionally, when the Internet-based client computer tries to authenticate to the on-premises AD FS Federation service endpoint name, such as https://sts.contoso.com/adfs/ls/, one or more of the following issues occurs:- You're repeatedly prompted to log on (more than three times) without a successful authentication.
- Access is denied, even though you enter valid Active Directory credentials.
- "403 page not found" errors occur.