Issue
How will Heroku know that we’ve enabled MFA for our SSO identity provider and that we satisfy the requirement?
Resolution
When you use a third-party identity provider (IdP) to log in to Heroku using Single sign-on (SSO), Salesforce currently has limited visibility into your MFA implementation.
In the future, Heroku may add support for AuthnContext attributes in SAML protocol to determine if MFA was used for a SSO login.