"Also, is it just for the authentication? Or are they providing self-serve password reset, lockout bypass, reporting and so on?"
Just authentication so that the users can open up Dynamics without having to login. No data passed for anything, no pwd reset, no reporting; basically the simplest possible SSO to open Dynamics without having to login.
".... what app?" it's a customized online store app (similar to Shopify)
"what method is the vendor quoting you on for the tokenization" I believe they're using active directory token to authenticate.
It's really irrelevant which method they use, we just need the simplest SSO to access Dynamics, we're fine with any type of password-based method if it's less effort, even if users having to reset the password every time they change O365 password.