...
IWA / Kerberos requires that client machines have access to a Key Distribution Center (KDC), which in the Windows world generally means Active Directory. For security reasons, AD is generally not reachable outside the local network/corporate intranet, making Kerberos mainly applicable within a company.
For more details also check out the How Kerberos works guide.
Combine Kerberos with other SSO mechanism
...