Hi Angela
Thanks for the background - some of our partners do use SAML2 so may be able to help.
The SAML2 authentication has been recently reviewed to included in Totara core - there are a few items on the todo list that will make this difficult to include into Totara.
regards