Hello Abu,
The Mobile SSO solution available with the SAP Single Sign-On product requires SAML Identity Provider for the authentication to the AS ABAP back-end of the SAP Fiori. This solution is available for both scenarios - when the user is accessing the system from inside corporate network and also when the user is accessing the system from outside corporate network.
It is up to your company to decide if you want to allow also external access but the SAML SSO is mandatory for both.
Regards,
Donka Dimitrova