Hi Dan
So, you haven't given up!
I was waiting for the IdP for an answer. Maybe they don't have an answer. So the final part remains unsolved.
The current state is:
- The existing users can switch between manual and federation authentication transparently - what they have (had) as Moode username is irrelevant ('course have to provide when logging in manually).
- New users coming from the Federation get their Moodle username set to the e-mail address. They can't fall back to manual log in unless I reset their auth method to Manual. Then they can switch back-and-forth but remember that when logging in manually the username is the e-mail address. Unfortunately on the Federation log in screen the username is without the domain. If I really want, I can delete the domain part in the Moodle username too. That is an unwanted, error-prone personal interaction and also not scalable.
Can live with that, can't do something as SP what my IdP does not offer! Therefore, PUT TO REST.