I forgot to add that if you have a signed-AuthnRequest-only policy in place you will inevitably run into vendors and implementations that either can't figure out how to sign an AuthnRequest or are unwilling/unable to issue AuthnRequests at all anyway. It will significantly reduce the pool of services that your IdP will be able to work with.