There are multiple solutions. First, if you change the "username" attribute from user.email to something like user.displayName, you can log in using SAML even when there is an existing Meraki account using the email. I do this for 100% of the SAML configurations I do. If you are happy to say all your users have the same permissions in all Meraki Dashboards you look after, you can make this simpler. Much simpler. If you copy, in the Meraki Dashboard, the SHA1 fingerprint and the "SSO Login URL" to any other Meraki Dashboard, and create the same SAML login roles - it will work. It will allow you to SAML login to any of those orgs. When you go to login, it will show you a list of all orgs you have permission to access, and you just click on the one you want to use. No changes in Entra ID required. Would this nice and simple configuration be sufficient?
... View more