Such that when you browse to any of the K2 sites (Designer, Workspace, Management), it will prompt the user to select the desired login method:
You will likely need to configure the Claims and Realms mapping also.
For the AAD Issuer, you can usually upload the K2 for SharePoint app to SharePoint Online App Catalog and run the Registration wizard, which will register the AAD Issuer for you.
Please also note that when you have different Security Labels, such as K2:DOMAIN\bob and AAD:bob@domain.com, this is seen as different users in K2, even if this is an AD account and AAD account for Bob: