Client access ldap filter

Hi, is there a possibility to limit access to the OID-client for a specific ldap group in Keycloak? That is, so that only a certain group of users can access a specific service, as is usually done using the ldap filter? I tried using roles, but did not achieve the result.

2 years have passed since the post, maybe something has changed? The problem is still actual…