I don't think it's their problem to solve though - IMO if Apple can't sort their **** out to properly manage credentials in this sort of scenario where you have multiple logins under a single second level domain, people should be complaining about them, not Workday and doubtless numerous other SaaS providers for which the same presumably applies.
What's the alternative, create thousands of new domains on a per-client basis? That feels like it introduces other problems that could also impact the end user.