First SAML JIT login blocked — groups assigned after unauth_app_access_attempt; second login works

HI,

Have you tried out Federation Broker mode - Federating the identity & access management with 3rd party IdP (race condition issue)