In 11.3, we had IWA set up alongside Anonymous access and it worked seamlessly. If a user has an account in portal, it would log the user in using IWA. If a user did not, it would still allow anonymous access if in-network to view maps and apps.
Since upgrading to 11.5, IWA does not happen automatically and to perform any administrative tasks or access the portal, users now need to login manually with their domain credentials.
Any reason why this might be suddenly happening? No settings were changed on our end. In IIS, both anonymous authentication and windows authentication are enabled, and this was not previously an issue. It is my understanding that if you only have Windows authentication enabled, users all need named accounts in portal, which we're trying to avoid by just using anonymous access for simple map/app viewers.
