

If you are not enabling the SSO for the app then you can manage the identity assignment group by group basis and can also create users in the slack manually. You assign the user to the application for SSO and has enabled the user provisioning it will provision the user. In Provisioning there is an option to provision the identities which are assigned to the application. If you are using SSO then you are forcing to use Organization credentials and in that case you have to assign the user to the application. Here is are you implementing SSO with it or not.

If you are adding local users in Slack then those will also work but question

When you setup the user provisioning between Azure AD and Slack then here it is considered that Azure AD is a master of identities and Azure AD will push the identities to Slack.
