Today a user that is automatically created using integrations / API is disabled by default, and the only way to activate it is by doing that for every user using the UI / API, and if a disabled user tries to login using SSO the user is blocked from access. Ideally, we would want the first SSO login to activate the user, without sending an invitation