When you enable the Active Directory Federation Services (AD FS) Windows token-based agent, authorized security tokens and ...

When you enable the Active Directory Federation Services (AD FS) Windows token-based agent, authorized security tokens and authentication cookies can be sent only to Windows token-based applications that are managed by this specific Web site, virtual directory, or application. 

To enable and configure the AD FS claims-aware agent, you must use the web.config file for the claims-aware application.