Consider only having a single Web Application which contains multiple tenants with different urls.
Now configure a Trusted Identity Provider for that web application, will this require the ProviderRealms be configured for each tenants' url address, or simply just not supported?