The user still has to set a password, but if you have them required to sign in via SSO they won't actually be able to use it when signing into that role. It's still not best practice to just leave a temporary password, since if you later assign that user a non-SSO role they will use the password they set to log into that role.