We use SAML for login. But we still have to use a certain amount of time on administering users.
  1. We have to create all users who should have access, manually and assign permissions.
  2. We have delete users manually
  3. We don't have a central view of which tasks/risks/Supplier/contracts etc. a user is responsible for when we delete a user.
Both Creation of users, deletion of users, administering permissions, should be based on AD/M365 groups.