Per https://github.com/spring-projects/spring-security/pull/7260#discussion_r319314499 it may be a good idea to propagate an `Saml2AuthenticationException` in the authentication provider with validation details. This can be caught in the authentication entry point, or other location, to influence UI rendering or messaging.