Hi,
For such configuration, i recommend to use multi domain sso instead of single domain sso.
In your configuration, you have to configure multiple policies, customization.... and the user is able to authenticate on multiple URLs.
With multi domain sso, you can configure login.test.com as primary URL.
when the user authenticate on this URL, display a webtop with links.
When the user first request app1.test.com, he is redirected to login.test.com to authenticate then redirected to app1.test.com
This mode allow to set different sso profiles based on the host.