I think the only metadata provided up front by BigFix would be the redirect URLs:
The redirect URLs are added to the relying party trust indexed, with binding HTTPS_POST, and in this format:
https://<WebUI_server>/saml (for the Web UI server, assuming that it listens on port 443)
https://<Web_Reports_server>:8083/saml (for each Web Reports server, assuming that they listen on port 8083)
https://<Bigfix_server>:52311/saml (for the BigFix Console)
There may be metadata exchanged behind the scenes after you add the IdP Entry Point and Signing Certificate to the WebUI.
I’m no SAML guru, but the steps outlined in the documentation worked for my customer.