Hi David - when creating the connection within Fusion, you need to log in with the Fusion Service Account credentials vs. the Fusion logged-in user on the pop up screen.

You need to be able to access the account of the fusion user, so it's recommended that you create a federated email address that can be logged in via SSO and represent a service account (e.g., workfront@{companydomain.com}) OR you can setup the user account in Admin Console as an Adobe ID instead of federated and use an email and password to authenticate.
The user doesn't need to be a part of fusion within admin console since you are authenticating the connect from the scenarios.
I'd recommend using an incognito browser so that it doesn't actively try to log in as you.