Anyone using AD groups as SSO mechanism to allow users access to Orion? 
If I configure a AD user in Orion and access the Orion website from a computer logged in with that account everthing is working fine - the user gets direct access to the system after the Challange Response dialogbox, the moment I remove that user and instead add a group where the same user is a member we only get to the formbased login after the challange response dialogbox. 
Running 11.5.2 with Orion platform 2015.1.2 and hotfix 6 
/Kaj