I can tell you from extensive testing from within UAG, AppWrap and the SRA for making internal websites available through the portal, that it is not a cookie issue, as I have testing that scenario. There appears to be only one ASP.NET_sessionId which has no bearing, UAG is passing it without issue. The actual fault lies in jquery.min.js, parseJson function, this part of jQuery onwards causes the browser to refresh. At this point I stopped testing due to time constraints.