Embedding paid content from one domain into another (i.e authz is needed to prove rights to access), it's common to store the session data in a cookie for the embedded site, at which point it's a third party cookie.
More concretely my particular case is to do with learning management systems which commonly use LTI to embed external content (outside of the US at least). That external content is hosted by some other system (can be another LMS) which usually store their session information in a cookie just because that's how it's always been done - The solution is to not use cookies, it's not needed, each resources can re-auth over the launch protocol (LTI) anyway, and for individual frames to be able to continue navigation/access - the session info can live anywhere else, in the URL for old fashioned navigation, or as part of the initial request body if subsequent requests are done over AJAX.