I wasn't able to find a direct answer, here are some relevant sources:
questions-help-bugsEntra ID Groups claim via Zitadel: Shows how to use ZITADEL Actions to propagate Entra ID group information into tokens by storing group data in user metadata and then adding it to token claims.
Map roles from external IdP to Zitadel roles: Discusses a GitHub issue about mapping roles from external IdPs like Entra ID to ZITADEL roles, with a workaround using Actions to capture roles claims and add them to tokens.