However, there are some situations where SAML integration may be the better choice:
Require SecurID as the primaryauthentication method and AD FS is running on Windows Server 2012 or 2016 (the agent can only provide additional/secondary authentication unless AD FS is running on Windows Server 2019 or later).
Require FIDO token authentication (FIDO is not supported by the agent).
Prefer not to install and maintain additional software on your AD FS server(s). The agent must be installed on each AD FS server in your server farm.