To set up a SAML Authenticator the first step is to add the service to your configuration
Then add the configuration for the correct attributes to rerieve the data from. The defaults give a good idea of what is needed. An optional group prefix can be provided to prefix a string to the group names returned. To be able to differentiate from groups received from the authenticator and groups created locally if there are ones which have the same name as a local group this will be required for that group to sync correctly.
Once your SAML authenticator is set up and is configured to run on a host, the next step is to hook it into the user interfaces.