Email domain mismatch using Google Workspace Enterprise Connection

Unable to authenticate a user unless there domain is whitelisted. Docs say that should only matter for Identity First login flow which I do not have configured… not sure what the issue is. When I whitelist the domain it works but that is not scalable for this type of application.

Basically this but I dont see how it was resolved. Google Workspace not working with multiple domains