It is definitely possible, but you'd need to use an iRule for that.
when ACCESS_POLICY_COMPLETED {
log local0. "Policy Completed"
switch -glob [ACCESS::session data get session.server.network.name] {
"bobscloud.company.comp"
{
ACCESS::respond 302 Location "/saml/idp/res?id=/Common/bobscloud.com"
}
}
}
The value you put in the ACCESS::respond should match the name of your SAML resource that is placed on the webtop - I named it bobscloud.com for you. Essentially, you're forcing a user to automatically hit the webtop-based IDP-initiated connection without seeing the webtop.