The whole backend authentication scheme must be based on Kerberos, as this is the only kind of authentication supported by ADFS for Non-Claims Apps. Each Web Application has to publish a Kerberos SPN ...
Optionally, the internal ADFS server may coincide with the Active Directory Domain Controller server ... For example, if Shibboleth wants to provide the User Principal Name (UPN) as a Claim in the ...