Our authentication to Confluence is handled by our own SSO by using a session cookie. The SSO also control the authentication to the core system(s).
Now we're having an issue with cookies not being enforced properly with Internet Explorer, and we've identified that the problem is due to a lacking Privacy Policy (P3P). We are not implementing this for the SSO and Core systems (all running on IIS). But the story is somewhat different for Confluence.
Now, I've opened a question on Stackoverflow for this issue as it wasn't as easy as I first imagined: http://stackoverflow.com/questions/19855946/turkey-urlrewrite-filter-on-tomcat-will-not-set-p3p
I appreciate all the help I can get on this issue.