That first redirect send users to correct URL for login, “ballmer@corp.contoso.com” might have to go “server23.auth.contoso-logins.com” and that first next button works like a mini search engine to make that work.
Perhaps the most contributing factor that kicked off the chains of event that resulted in the mess of that chain of the event is that sometimes the “domain” part of RADIUS or other authentication servers(called “realms”) don’t resolve, because they aren’t FQDN, in the same way com.companyname.myapp1 never is. On top of that, you would want to be able to log in with non-matching realms in ID, such as ballmer1@microsoft.com on contoso.com, so it’s always just a long String with at signs and dots with no discoverability anyway.