If the SSO attribute used to authenticate is changed (e.g., from email to username), are users automatically signed out of the platform?
The attribute used by SSO to federate is not visible to users. This means if the attribute is changed, e.g., from email to username, SSO users who are currently signed in will remain signed in as long as their username correctly matches the NameID sent by your organisation’s chosen identity service.