You request is very interesting and I think you may need some SAML package to get IIS to pass your security token to Tomcat, you could create Asp.net application and use AD provider but I am not sure if IIS can pass the token to Tomcat but it uses LDAP so you could just write code to do that. You could also ask if your employer have implemented any single sign on those are the packages that uses Token servers to propagate the security token from one hop to the other. And I think most vendors don't pay for the relevant math so your web application code may break. But I could be wrong.