Rancher 2.10.x and OKTA

hi

We have racnher with 2.10.x on K8 1.31.x and we testing OKTA with this.
Each time the OKTA is enabled we get the error

[rancher-799c68dffd-5fmmz] 2024/12/13 16:21:53 [INFO] Refusing to reset the config and clean up resources of the auth provider okta because its auth config annotation management.cattle.io/auth-provider-cleanup is set to rancher-locked

Any one else have this issue.
We are on Rancher 2.10.0 and K8s is 1.31.3

Also occasionally get this in the logs

[ERROR] SAML: Unique ID field is not provided in SAML Response

rgds sanj