I'm already hearing squawking . . .

We have configured our AGOL account to use the Active Directory Federated Services. That being said why is it when I am using the Collector application I first have to log into our network via VPN (with AD credentials) then when I go to my tablet to view my maps I have to log into our AGOL portal (with AD credentials) and then if the map contains a secured service, I have to log in to access that secured service again with AD credentials?
Do I have something configured wrong? I thought the whole purpose of Active Directory Federated service was for "single" sign-in.