I should add, if they really meant "every time the user is actually prompted to login", that would be possible, there is a way to know if SSO happened or not. Not commonly used, but it's in the audit log, so it's definitely "known" internally in a public sense. -- Scott