It turns out the setting I was missing was:
response_type=token id_token
which needed to be added to the Enterprise Connection (in the SP) under IdP-Initiated SSO | Query String
It turns out the setting I was missing was:
response_type=token id_token
which needed to be added to the Enterprise Connection (in the SP) under IdP-Initiated SSO | Query String