It would make sense to have this option on the authentication settings page of the profile rather than hidden away as a registry setting.
There is also a high liklihood that people will want this enabled by default if using a SSO provider.
They have to get it to work first…