I have problems with a single user in an intranet application. The client side is a WPF application which communicates with a ASP.Net Web API Web Service.
Wireshark will inspect all traffic. I will break down the ticket from ASN.1 to a displayable tree structure. You'll see what mechanism is used in your case. Additionally, you'll see all the Kerberos traffic, e.g., your TGS-REQ.