replied on November 30, 2022
We use Sailepoint as our SSO at University of San Francisco. It works fine, but Laserfiche is not exactly easy to set up with SAML. I've had experience with Shibboleth (what Sailpoint uses) at a few different institutions, and was never easy. Laserfiche was built from the start with Active Directory, and while SAML support is better it's very much 'bolted onto the side.'
The biggest weakness in using SAML instead of AD is there is no automatic 'tombstone' of inactive accounts with SAML. We had to use workflows with a few custom scripts to feed a list of inactive users into LFDS to remove licenses from accounts that are no longer active.
Also, if your SSO team feeds Laserfiche email address for the LF username it will append the domain with an underscore replacing the @ symbol. This presented a huge issue with integrations from other systems that had just the username to assign Forms tasks.
Laserfiche had a username as smith_usfca.edu, but when we pull that persons name from another system and try to use that to assign a forms task (Lookup Rule in forms) it comes in as just 'smith' and the user task assignment fails.