SAML on demand user provisioning is an ok system for bootstrapping a new user on initial login, but generally isn't meant for keeping identities synchronized across two platforms. That role is better filled by SCIM, which provides a standardized interface to not only provision a newly created user, but also to synchronize a user's attributes in an ongoing manner. Based on an initial exploration of VMWare's Identity management documentation, I don't see that it contains a mechanism for their own Synchronization engine to leverage SCIM APIs, although they do include their own SCIM APIs to allow another system (like Azure AD or Okta) to serve as the reference for a user's identity.
------------------------------
Richard Schott
Genesys - Employees
------------------------------