Hi, Hannah.
>Ideally, we would like to avoid having to create a user in Gluu - any help would be appreciated.
Not sure it's possible. Gluu expects any user has an LDAP entry locally. During different flows it will be used as a source of attributes to send to remote party.
I also remember that our developer mentioned before, that during authentication a check for `gluuStatus` attribute of logging in user is performed in local directory, to make sure it has "active" assigned to to it.