Omnivista 2500 SSID with 802.1x

I have an SSID running 802.1x , but now I need to restrict the access to users add to the AD group “wifiuser”.
I can have an active user on my AD, but if he doesn’t belong to the “wifiuser” group the access must be denied.

Can this rule be set on " UPAN > Authentication> Role Mapping for LDAP/AD" ?

I think it is possible to use the memberof attribute and accept or reject the user