Right now, users have to be very familiar with the implementation to even begin troubleshooting.
Sometimes things fail silently with no indication to the end user that something is wrong or went wrong and the logs are not always useful on this front.
For example, if the SP sends the wrong redirect url to the IdP where Liferay is acting as both, nothing gets logged and it just fails silently.
It may be the best to sweep through all the error cases and create a better troubleshooting system. At the UI but at logging also.