Cookie Domain and SameSite Policy Are Part of Cross-Subdomain SSO
One identity portal can protect many subdomains only if browser cookie scope and request behavior match the intended trust boundary.
One identity portal can protect many subdomains only if browser cookie scope and request behavior match the intended trust boundary.
A session can have an idle timeout, a hard lifetime and a trusted-browser persistence policy at the same time.
Cross-subdomain authentication only works predictably when cookie scope and redirect boundaries match the domain design.