Several users are failing to authenticate via SSO despite valid Azure AD assertions. The system doesn’t create the user profile during JIT, and the logs indicate a mapping mismatch for the role attribute.
The SAML response contains the following claim:
<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/role">
<AttributeValue>GC_Agent_Tier1</AttributeValue>
</Attribute>
A similar issue was mentioned in a community thread regarding attribute case-sensitivity. The admin UI shows the configuration is correct, but the users still can’t log in.