Assigning Azure AD roles to cloud groups is generally available now. isAssignableToRole attribute on group object is in Graph v1.0 and latest version of AzureAD PowerShell.
Seemingly simple, but amazingly complex to build. But finally...
docs.microsoft.com/en-us/azure/ac…@StuartKwan