Hi Peter,
To have more information about your issue you should configure the trace in Secure Login Client. Please check the implementation guide here http://help.sap.com/download/sapsso/secure_login_impl_guide_en.pdf chapter 2.6.9 Tracing Secure Login Client.
Activate the Developer Traces and repeat your issue.
You can also check if the Server SNC Name configured in SAP GUI is the SPN of your Service Account in AD.
You can check if you get a kerberos ticket from your AD wiht the command "klist" in your client workstation.
KR
Valerie