So, what I ended up doing was hitting active directory to pull users' mail attribute, indicating their SSO ID. So, we still have to grant them access to the tool, but using the right address (cause some people have up to 8-10 email addresses here).
Having said that, the provided documentation still indicates that roles should be directly granted to SSO users, rather than simply passing authorization.