Unlike traditional SSO, CSP does allow for manual accounts to sign into CSP once Federation is enabled.
The caveat is that the account must sit under a separate domain from the domain that is currently federated.
As an example, if a CSP tenant has Users under domain1.com, and domain2.com and domain1.com is enabled for Federated Sign In (SSO) all users from domain1.com when signing in will be redirected to the IDP to sign in.
Users from domain2.com will still be able to sign in via - console.cloud.vmware.com using their manually created set of User Credentials (Email and Password)