I don't think providerHost is used any more, as I had accidentally configured it with the client's host, and nothing happened. Maybe the provider host is used to look up the correct application if going directly to the login domain, such as login.your-app.com, but I'm not sure that's useful, as it wouldn't have any secrets from the client at that point, so a login would fail anyway.