UPDATE ......From Tuesday 8 April 2025 we have changed the way that Single Sign-on works on this wiki. Please see here for more information:
Update
...
If you're using FreeRADIUS 3 and base your config on the new default virtual-server or modify your default virtual-server instead of defining a new one based on the examples provided , you need to pay attention to the filter_username in the authorize section. FreeRADIUS 3 has this enabled by default. You should disable (or modify) this policy because it prevents people from with mixed-case usernames (from other IdPs) to authenticate.