Per #7260 (comment) it may be a good idea to propagate an Saml2AuthenticationException in the authentication provider with validation details.
This can be caught in the authentication entry point, or other location, to influence UI rendering or messaging.