How does ADFS identify that a user is coming in via a external connection thus only offering certificate or forms based authentication ?
I have users that connect via a VPN which uses a shim and they share a external IP e.g 200.x.x.x. so they are presented to ADFS as that IP