Add support for urn:oasis:names:tc:SAML:2.0:nameid-format:transient format in SAML Identity Provider brokering. This touches both admin console (NameID Policy Format in Identity Provider configuration) and the code that handles users.
Brokered Shibboleth is configured to require
that option is not available on keycloak configuration. Keycloak configurator should allow this option and also allow AllowCreate to be setted in case of transient.