Sorry, I do not follow ... I have it setup like this :-
Primary domain : primary.com
Additional domain : secondary.com
ZCS Server name : office.primary.com
Virtual Host : office.secondary.com
Secondary user connects to
https://office.secondary.com and just logs in with their user name only; not the user FQDN.