Sonatype CLM Server - Security Administration
Mapping a group to a role utilizes elements that are configured via the LDAP System Preferences area. If you go with the default options, groups will be included with the search results. That is, when you enter something into the Find User field, both groups and single users will be returned.
However, because the size of LDAP implementation can vary, you may want to consider not including groups with your search results. This option can be adjusted when using Dynamic Groups settings.
Making this change will then allow you to manually enter group names. However, when entering groups this way, no search or validation will be performed.