There is a krb5_map_user option, but at least in sssd 1.12 it does not appear to be possible to combine the Kerberos auth_provider with the local id_provider.