Your comments

You should be able to already (we are using Azure AD using SAML with Groups assigned to it). You will need Azure AD Premium P1 to assign a group to an application.