Which IdP are you using? Your IdP needs to include the role attribute in the assertion. The role attribute value must be in the format of "cn=myrole,dc=myfqdn,dc=com"
AFAIK, The userToRoleMap stanza is only used in place of Attribute Queries. For initial authentication your IdP still needs to pass the role attribute. Did you also set the skipAttributeQueryRequestForUsers option for authentication.conf?