It accounted for well over half of our company’s support tickets. The biggest problem is nobody on the customer end wants to champion getting it setup. When things go wrong, they just throw their hands up.
The core of SCIM/SAML is relatively simple, but there are tons of different ways companies can configure things.
* Younger companies tend to use a "modern" identity provider, Okta, Google Workplace, etc. However, the owner of SSO system doesn't tend to be an SSO expert. These setups normally work "out of the box", but require a bit more generic guidance since the person setting it up only deals with SSO occasionally.
* Older companies have the internal expertise, but often use legacy configurations. Many time, this is just a matter of figuring out what the two different system call various fields. However, the range of errors can be huge, so you have to explore a bunch of stuff.