Refer to the exhibits. 
Option B and D make sense to me. If SAML Single Sign-On isn't set to Manual, sometimes authentication won't work right with Security Fabric. Also, management IP being off could cause join issues if the devices can't talk directly. I think these are both plausible reasons for that Pending status. Open to other takes though.
I think it's B and D. SAML could block comms if not set right, and management IPs might matter for Fabric joins. Not totally sure though, maybe missing a detail here. Agree?