Are you going to be setting up an IDP just for a single cloud service? Reason I am asking is that it's pretty rare that customers setup a single cloud-based service in their environment - even if you start with one, there will always be more later one.. :)
Regarding bobscloud.company.com - your cloud-based service should be able to take care of it for you - so you will hit it, and it will automatically send you to your local IDP and after authenticating to APM, you will automatically receive a response/assertion sent back to the cloud service