If you prefer CLI or don't want to provision the APs to new groups, here is an alternative. This will create an Open SSID named SSIDName. Connected clients will be assigned the "authenticated" role. I've also added the snippet to apply this Virtual AP to 2 APs of your choice. Replace quoted items as necessary. Add other settings as necessary, band-steering, bc/mc optimization, etc.
wlan ssid-profile "open-ssid"
essid "SSIDName"
aaa profile "open-aaa"
initial-role "authenticated"
wlan virtual-ap "open-vap"
aaa-profile "open-aaa"
ssid-profile "open-ssid"
vlan "111"
ap-name "AP1Name"
virtual-ap "open-vap"
ap-name "AP2Name"
virtual-ap "open-vap"