Ok, got to the point where my QATrack landing page gives me the option for single sign on. However, when I click it it just thinks for a while then does nothing. No errors.
The auth log records this, in case this means anything to anyone. IT department swears up and down that they followed the docs, and sent me screenshots of the powershell checks which do look like "qatrackplus" is a bona fide clientId with the correct redirectURI for my test server.
Auth log dump below, in case this means anything to anyone... I'm giving up for now, thanks folks.
-N