SAML equivalent to OIDC hosted domain

Hi, I’m trying to figure out how to do a hosted domain filter when authing users to gsuite via SAML.

The problem that I’m running into is that if a user has multiple google accounts that they’re logged in with (in chrome for example), the google account chooser page is displayed and it shows their logged in accounts. However, only one of them will work (which is the account with their company domain). Due to this, any time the user session expires in keycloak, they are presented with this screen again.

This isn’t an issue if the user is logged in with only one google account as it will be automatically chosen. The user will be automatically redirected as they won’t have to go through the account chooser process.

OIDC has a solution for this by providing the hd, or hosted domain that will automatically filter the user’s account domains. Is there an equivalent for SAML that was can select to force the user to only be able to use their company account?