Today, i can configure SSO for SAML / OIDC / .. in the admin client.
What i cannot do - is configure different SAML service endpoints for different clients.
In our case, this means we cannot use SAML with webCube & winCube, as both use different ACS URLs. An IDP should be able to service that, according to SAML specs - DOXiS behaves correctly - but our IDP simply cannot. It services exactly ONE ACS.
Given the possibility to use multiple SSO configs - one specified for each client / as default, would allow us to better deal with non-conformant IDPs.
Also - it might allow for easier control on who can use which client.