Do you have only one connector in your system? If this is the default connector, its IDP URL is set to the Horizon Workspace FQDN. Hence, if you go from Horizon Workspace FQDN, Kerberos Auth will not work.
Can you try the following?
In the connector admin UI, click on Identity Provider on left side navigation, change the URL to Connector's FQDN.
If you want to support two forms of auth - kerberos for internal users, Username/password for external users etc, you will then need to install an additional connector. Please see the installation guide for more information on adding a new connector.