SAML configuration is tedious and validating both the identity provider & WebSphere configuration are important. A potential cause of this error though is when the identity provider and Maximo loginid for the user do not match. Since you were previously LDAP, your authentication mechanism was likely the sAMAccountName. Identity providers often provide email address instead. This can be configured to provide alternative fields though.
I would try to update the loginid on the user to the email address and see if that resolves the issue.