First, Active Directory or the full SAML piece? It sounds like the full SAML piece if you're talking about Windows groups.> Settings > Logins you have to set up the SAML configuration.
Then, in the Group, you have to enter the group identifier that you've chosen to use in AD (name, GUID, etc).
And of course, the Windows pieces have to be setup in AD first.
We've done straight AD without SAML before, we're on SAML for logins now and we're about to implement SAML for groups (tests are successful).
Abe.