For troubleshooting purposes, you should disable Extended Protection for Authentication in IIS by following one of these two options:
Option 2 - Use PowerShell to set this at the farm level.
Open PowerShell Command Window Load ADFS PowerShell SnapIn
Add-PsSnapIn Microsoft.Adfs.Powershell Set ADFS to disable EAP at the farm level
Set-ADFSProperties -ExtendedProtectionTokenCheck:None Restart ADFS and IIS
IISReset Net Stop ADFS Net Start ADFS
You should now be able to successfully capture a Fiddler trace from an
AD FS 2.0 scenario and credentials are accepted at the first HTTP 401 challenge.
Be sure to revert your changes once you are finished troubleshooting with Fiddler.