Hello @Cloudy and thanks for reaching out. For the sake of simplicity my recommendation is to use Azure AD B2C as the main IdP and federate your current one and/or others. You can you use both SAML or OIDC. Although Azure AD B2C does not support SCIM you can create your own implementation using the MS Graph AP. Out of the box, SSO will be enabled for the whole tenant.
Let us know if you need additional assistance. If the answer was helpful, please accept it and complete the quality survey so that others can find a solution.