We have multiple domains. Can we use SAML across all directories?
Yes, you need to make sure that the domains are in a trusted relationship (bi-directional trust) with domain wide authentication. The following steps are needed:
1.) Conditional forwarding in the DNS for the root domain (domain.com) as the adfs server is named adfs.domain.com
2.) Adding the ADFS server name (adfs.domain.com) to the trusted sites in the Internet Explorer of the clients to make sure the windows authentication works
KBA , BPI-SIG-CA-SEC-SAM , SAML 2.0 for SAP Signavio , How To