Mapping multiple users from SAML IdP to same keycloak user


I have an external Identity Provider ( SAML / Shibboleth ) and would like to map all remote users (i.e. different NameIDs in saml ) to the same Keycloak local user ( for granting anonymous access via a single “university” pseudo-user ).

However Keycloak seems to associate a single “Provider User ID” ( = NameID of the first remote user ) with the local user and can’t map further remote users to the same local user.

I would appreciate any help.