Auth0's Fine Grained Authorization is in developer preview.
If it would:
a.) Perform group assignment based on SAML attributes (like Okta's group rules), and, b.) "natively" support SAML Federations used in the Higher Education space (which Shibboleth appears to be the only thing that supports)
I'd sign up tomorrow and start migration of my 150k users.