If you don't want your stuff used by small orgs that can't afford to pay, that's a totally reasonable standpoint. At the same time, though, if it's good they probably will use it despite not having SSO, and so that decision makessecurity (something that, by and large, benefits everyone) into an opt-in luxury good. Speaking only for me, I'd be uncomfortable espousing that as a philosophy.
But as we have seen, companies are not doing enough to secure the sustainability of the open source software they rely on for their businesses, and I think a balance needs to be struck.
SSO isn't where to try to bleed that pig though, I think, to the point where for team-based systems it is probably more proper to disallow anything else (and maybe make them pay for guest access outside of their domain!).