Azure AD SAML JIT Provisioning - User Role Mapping Failure

Several users are failing to authenticate via SSO despite valid Azure AD assertions. The system doesn’t create the user profile during JIT, and the logs indicate a mapping mismatch for the role attribute.

The SAML response contains the following claim:

<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/role">
 <AttributeValue>GC_Agent_Tier1</AttributeValue>
</Attribute>

A similar issue was mentioned in a community thread regarding attribute case-sensitivity. The admin UI shows the configuration is correct, but the users still can’t log in.