Thanks for sharing. I just tried setting this up with Intune and EntraID. I get an additional auth popup after clicking signin to iCloud. So user has to enter credentials 2x. Wonder how Okta respects the previous sign-in session even though you mention it is opening in a incognito browser in background.