An IdP must be reachable directly by the client browser. If you can configure a proxy for IdP URL, you should be able to make it work. But be aware that you won't be able to authenticate at the Edge if the WAN is down.
We could do this by adding Entra as a Identify provider on the Edge as well, and the gateway will need a proxy or wan access to the IdP URL. Is that a good summary, there is no way to do this within the gateway network and central server?