Authentication to a PSU-App with a AD-group?

Product: PowerShell Universal
Version: 5.6.13

How do I use a AD-group for users for access to a app?
I have tried without AD and just used roles but then users with no role can se all apps. I need to give identities roles if i want users to not access apps. New users can see anything if they have no role. Someone have a solution? Best would be to use a AD-group but cant get it to work.

You would need WS-Federation | PowerShell Universal

I use claims with AAD instead. So I have no experience with WS-federation setup. But this is a starting point.

How did you make that work? I want it instead. Do you use IIS?

It is well documented here : OpenID Connect | PowerShell Universal