Cookie Domain and SameSite Policy Are Part of Cross-Subdomain SSO
One identity portal can protect many subdomains only if browser cookie scope and request behavior match the intended trust boundary.
One identity portal can protect many subdomains only if browser cookie scope and request behavior match the intended trust boundary.
Cross-subdomain authentication only works predictably when cookie scope and redirect boundaries match the domain design.