Hi Carver,
It sounds like you might have already gotten your answer, but just in case anyone else has the same question, here's what Support suggests.
This is something you will need to configure at your Identity Provider. Within your Active Directory, you will need to create a group who has access to the Workfront app via SSO and then add your users to that group. If you require all Workfront users to authenticate via SSO, you will want to bulk edit your list of users on the People/Users page within Workfront. You can select all users, Edit, then check the Only Allow SAML 2.0 Authentication box, then Save.
Thank you,
Kyna