Allow Admin to Delete User (including personal vault)

Session revocation would be handled by SAML’s Single-Log-Out mechanism, for which Bitwarden states "Login with SSO currently does not support SLO. This option is planned for future use…". Until available, one mitigation possibility is to set a short short session reauthentication timer (e.g. 15 minutes – if Bitwarden supports it), and then silently reauthenticate on the IdP side for however long you are comfortable without re-MFA’ing them (e.g. 9 hours).

SCIM is provisioning/deprovisioning
SAML is authentication/login/logout