1) are you creating users manually or through AD sync ?
2) either case, look at the accounts tab for the user and there should be two logins defined . One being Defaulthauth with domain\user id and another one with web authentication domain with only user id.
3) The login with web authentication is used for Windows integrated authentication.
4) When a users try to open the link, (use google chrome, if you use i.e you have to make changes to accept IWA) , the keytab (if you use spn ) will be matched against realm to generate the token (once succesful ) .
Best,
Sai Korrapati
Sai Korrapati