If the same Active Directory used by IdP is available on-premise, you can configure it as an authentication server and use it as Group Affinity server under SAML IdP realm. In this case, SMA will use SAML IdP to authenticate users and on-premise Active Directory for group checking. For more details on how to add Group Affinity, see Enabling Group Affinity Checking in a Realm
After enabling Group Affinity for SAML IdP realm, you can add "Mapped Accounts" by "Browse Directory" or "Dynamic Group" options and selecting SAML IdP realm.