Workaround observed: delete the local Kimai user; then log in via SAML — Kimai creates a fresh user from the assertion and authentication succeeds. Admin-created user workaround: Deleting the user and ...