Firmware 17.8 (same issues with 16.16)
Set up AnyConnect Azure AD SAML. One user authenticates successfully and receives 'Can't reach this page' in the Cisco AnyConnect Login box after providing MFA.
When I test with my admin account, this first time it hangs after successful MFA and finally gives a 'CSRF token failed' message. Then each time I attempt afterward it will successfully connect. Here is the AnyConnect log showing the first failed attempt and the subsequent successful attempt:
I notice the first time, I don't see the banner message. Both users testing (including myself) are in the Azure AD enterprise app group.
My AnyConnect / Azure AD settings: