Glad it's working. Helix uses the SAML NameID to look up or provision the user account. With persistent, your IdP sends an opaque ID that doesn't match any email on file, so Helix can't find your user — and the just-in-time provisioning logic creates a fresh user, but at the next login it tries to look up the same opaque ID, doesn't find a match (because emails were used originally), and bounces you back. The loop is the symptom of that mismatch.
For future migrations: always use emailAddress NameID, and test with one user before flipping the org-wide switch. We document this in the SSO guide. Is there anything else I can help with?