Answer
Yes, you can still use SAML for Web Auth,
and NO, you do not have to create an id vault if not using id files
for encrypt/decrypt mail operations. For the Web there are two levels
of SAML configuration, the first level is to authenticate web users
and a second level is to allow web users authenticated via SAML to use
SAML to pull id files from the vault, in your case you do not need the
second level of SAML configuration and can use SAML to authenticate web
users.