Under SAML, clients can initiate Single Sign-On (SSO) and Single Log-Out (SLO) at either the identity provider (IdP) or the service provider (SP). You can control whether the service provider accepts SAML messages initiated at the service provider or identity provider. Thus you determine what kind of access clients have to your SAML landscape.