I've often wondered why there isn't a simpler identity provider service that does the thing that ~90% of applications need without all of the complex configuration.
Obviously you can make a product that only does really good username/password auth for example, but there's always more pressure to implement more things for another use case.