See https://github.com/spring-projects/spring-security/issues/10607.

Since not every tenant in a given application will use SAML 2.0 Logout, it should be possible to use saml2Logout in the DSL while indicating a null single logout service location given RelyingPartyRegistration instances.