>> My first thought, is this is something that would have to be configured on the Service Provider end.
Yes, that is always best for SAML SSO because we don't control SPs from IDP side.
>> I have seen it accomplished on an Identity Provider, but I fear the Gluu Management Application would overwrite such configuration.
I might have some answer on this question but let's see what you got, it might be really a good option! :)
Mind to share?