While I was never able to sort out seamless SSO, I have now managed to at least implement the SSO and a persistent authentication cookie so that users are only prompted after a sensible period of time. See link to separate question about the persistent authentication cookie. Persistent Authentication Cookie for External Membership Provider Umbraco 13