The product currently does not allow for this from the IM User Console interface as it typically only directly manages account objects on templates. Engineering is aware of the popularity for AD Group Management and is looking into it. For now options are:
Use Provisioning Manager and/or native ADS to create the groups first. If using native ADS they need to be explored in.
Or have IM PX Policies execute Microsoft DSADD/DSMOD type commands that operate against the AD itself.
Once the IM system is aware of those groups they can be added/removed to Account Templates which can be included in Provisioning Roles and then those Provisioning Roles can be added/removed to IM Users. Or again IM PX Policies that can add/remove groups to the AD Accounts.
But again there is no IM User Console tasks for managing AD groups as there is for managing AD accounts. This is true for all endpoint types where only endpoint accounts are exposed/managed via the IM User Console at this time.
- KennyV