The SAML configuration looks correct to me. With “Allow the module to create users” disabled, a successful SAML authentication without a matching Mendix account should result in:
“The authentication was successful, but there is no account available in this application.”
Mendix's SAML troubleshooting documentation also describes this as the expected behavior.
The interesting part is your log:
User lookup of 'Name' failed, this user principal does not exist in the Mx database.
This suggests the SAML assertion is being processed correctly, but the failure happens in the UserCommons CreateUserRecord/session creation flow. Since SAML 4.2.3 and UserCommons 2.4.0 are the relevant current versions, I would first verify the exact Mendix runtime version and confirm there are no older SAML/UserCommons Java libraries left in userlib.
If everything is on the supported versions and the issue is reproducible with a user that definitely does not exist, I would raise this with Mendix Support because the observed behavior differs from the documented SAML error handling.
Kindly mark this as the accepted answer if it helps.