If the PreviousSession handler is "turned off" (commented out in handler.xml), is there ever a time when an IdP session cookie (_idp_session) would still get written to the user's browser for any reason? -- Michael A. Grady Senior IAM Consultant, Unicon, Inc.