Primary/secondary sounds like you're possibly binding classic elements. Where possible for new implementations you should be considering doing this with AAA vServer and using nFactor flow instead. On the gateway(s) bind an auth policy that references AAA. "Matching policy not found while trying to process Assertion" -- when troubleshooting SAML issues, I strongly recommend the edge/chrome plugin "SAML Tracer" which can help identify the SAML bits the browser is processing. That said, it sounds as if the ADC itself isn't matching a SAML policy statement.