They’re implementing SAML SSO for Confluence Data Center and have a problem with username mapping.
They want to use sAMAccountName as the username (because that’s their standard LDAP ID), but Azure AD only sends the email address as NameID in the SAML assertion.
If they map the username to ${sAMAccountName}, login fails, because Confluence only receives the email and can’t find the user.
They tested a workaround by changing the LDAP username attribute in Confluence from sAMAccountName to mail and using ${NameID} in SAML, which works but is not acceptable long term, since all other systems use sAMAccountName.
They’re asking whether you have experience with this setup and how to correctly configure the attribute mapping in Azure AD so that Confluence can use sAMAccountName.