Cookie Domain and SameSite Policy Are Part of Cross-Subdomain SSO
One identity portal can protect many subdomains only if browser cookie scope and request behavior match the intended trust boundary.
One identity portal can protect many subdomains only if browser cookie scope and request behavior match the intended trust boundary.
Auth gateways need the original request context to decide and redirect correctly.
A longer browser cookie does not help if the server forgets the session behind it.
A session can have an idle timeout, a hard lifetime and a trusted-browser persistence policy at the same time.
A two-factor login system naturally records failed credentials, expired sessions and rejected access, so any single failure is not automatically an attack.
Cross-subdomain authentication only works predictably when cookie scope and redirect boundaries match the domain design.
Putting MFA in front of each application separately creates duplicated policy; Authelia gives the protected subdomains one identity boundary.