That's the type of feature that should be implemented as a plugin.
The problem with that is that it requires users to have been created inside postgres first, and that you can't manage group membership inside AD.