We are currently facing a sso scenario with a IdP as a service where we only have a limited access to it and support from provider. Our IdP does also not support definition of C