Mitchell,
Ah got it. Yes, this is actually an expected behavior and something we’ve documented. SSO User/Groups are not currently migrated as part of the Fling. The reason that the roles weren’t impacted is that you had setup a new VCSA which included configuring SSO and hence the default set of users (e.g. administrator@vsphere.local) were already configured and valid. Most customers stick to the default SSO Admin and don’t really use SSO for managing users but rather their own directory service like Active Directory.
In the future, we hope to also handle SSO User/Groups but for now that is a limitation with the Fling