I understand how I can configure an AGOL setting for "allow portal access" such that if a user on my 10.9 Enterprise Portal tries to add a secured service from my AGOL to a web map, the user can authenticate to AGOL using SAML Enterprise Login.
However is it possible to somehow configure the reverse (which actually seems like a more compelling use case). If I publish sensitive data to my Enterprise Portal, and an AGOL user wants to add it to an AGOL webmap, I would hope that they could use their Portal Enterprise login (SAML) to authenticate the item. As of now it just prompts for a username and password, no SAML auth prompt at all.
Any thought here?