Yeah to date how I've seen most user folder and/or plugins handle this was by mapping whatever the source labelled as "groups" to to roles. Often times there is a zmi manage page setup for managing this mapping as well.

Tres Seaver wrote:
Group -> role bindings *are* likely to be the domain of the user folder,
whether LDAP-based or not.

