Maybe not all, but kids pickup things fast. When I was young the school tried to block a popular flash games website, one lunch hour later and somehow we all learned how to use a VPN. I'd say I owe a lot of my technical ability to learning how to circumvent restrictions on school computers and whatever my parents tried to setup on the home computer.
It appears that many of the complaints in this thread are related to the complexities of SAML. I configure, manage, and troubleshoot many SSO configurations in my work but they are all OAuth2/OIDC based and find them really quite simple, easy to understand, and the RFC's a pleasure to read.
Has anyone used both SAML and OIDC in their career and could comment on whether I avoided a difficult time in SSO with SAML, or am I just unaware of the difficulties because its what I regularly work with...