so i'm having a strange issue with integrating our jamf cloud instance to otka for SSO.
when user-initiated enrolling devices with our myjss.jamfcloud/enrol URL we are prompted for our okta credentials, they are accepted, and then we receive a http 400 error instead of being prompted to download our profile.
BUT
if you open a new tab, and enter the enrolment URL again, it pushes straight to the JAMF profile download page... no need to credential again.
after that the enrolment all works as normal...
my question is has anybody else seen something like this and how did you fix it, so that we can get to the profile download page the first time...

