According to spec, when someone uses oauth to try and log into an existing account for the first time, you must require the user to login through their normal method and then prompt them to link the login account.
However, the identity provider cannot force you to do that, and there are many examples of apps which do not follow this part of the spec.