The SAML Federation one is where all the modern SaaS fall short. Its still SAML but it involves:
All the metadata for 100s of IDPs being downloaded and made available to enable
Publishing the SP metadata to the federation(s) which may involve fees.
Specific rules around metadata (attributes) being released and adhered to.
And if your directory insists on having an email addresses for a user, that might be an issue.
There's a reason why Higher Education businesses have cropped up around doing SAML Federation.
I have had a trial of FusionAuth, and it was great, just didn't solve enough of our pain points to justify a migration.