In Federation Partnership setup >> User Identification, under Federated Users column, you can select 'Group' from the User Class drop-down list associated with this AD user store.
Then you can specify the filer e.g: (|(mail=*@.example.com)(memberOf=cn=Employees,ou=Groups,dc=example,dc=com)).
Best regards,
Kelly