We got in touch with Google Support and they found the following: when accessing existing accounts, the SAML contains an additional attribute with the nickname. But when accessing a new account (new in Auth0 and Google), this attribute was an empty tag.
<saml:Attribute Name=“http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name” NameFormat=“urn:oasis:names:tc:SAML:2.0:attrname-format:uri”>
<saml:AttributeStatement xmlns:xs=“http://www.w3.org/2001/XMLSchema” xmlns:xsi=“http://www.w3.org/2001/XMLSchema-instance”/>
Not sure why Auth0 does not map the nickname correct with the new user. But Google Support said it was unnecessary to add this. So we removed it and everything worked fine.
We used the SAML from the documentation at https://auth0.com/docs/protocols/saml/saml-apps/google-apps , which incorrectly uses a mapping for nickname. It should not be there.