When the ADAL STS URL resolves to an internal ADFS server, and Integrated Windows Authentication is enabled in browsers, computers on which many users sign in to client applications may not authenticate the logon attempts. To avoid this issue, the browser must be explicitly configured to prompt users for their credentials in a given browser Security Zone. For example, a kiosk is configured in this manner. The account that is logged on to the operating system may be different from the user account that is used to sign in to the Skype for Business client. In this situation, you may see the failures that are described in the "Symptoms" section.
If you have kiosks on which the user who starts the Skype for Business client differs (that is, has a different account) from the user who is logged on to the computer, you may want to test the method of turning on the Prompt for user name and password option for these computers in Group Policy.