This has also blocked me on some HashiCorp work for a high profile customer.
Business case was moving to managing Vault’s various integrations “as code” to allow self service for users of Vault Namespaces in a massive, complex environment.
Whilst we are working on improving the AzureAD provider to support more resources and configurations, at this time SAML settings for Enterprise Applications are not publicly exposed via API, and so the only way to configure this is using the Azure Portal.