Azure SSO without Sugar Identity

SugarCRM Enterprise v14:

Hi 

Our CRM is hosted by a Sugar partner in the UK. The system is in effect 'on prem' as it is not in the 'SugarCloud' and does not have 'Sugar Identity.

We are in the early stages of planning to move to Azure SSO. Whilst we can integrate with Azure without SugarIdentity, and the direct SAML integration maybe a less issue-prone mechanism for implementing SSO in Sugar Enterprise than using Sugar Identity, I'd like to know the issues.

I think the issues are:

Role and Permission Synchronisation -  Assigning roles and permissions in SugarCRM will need manual updates, as there’s no native sync between Azure AD groups and SugarCRM roles.

SugarConnect: synchronisation may not will not work properly, authentication to SugarConnect will not be automatic and users will have to enter  their username and pw each time they want to use SugarConnect with Outlook.

Is there any documentation or guidance available for this style of set up? The only documentation i can find concerns setup with SugarIdentity.

Kind regards john