We have this use case where customer doesn't have on-prem AD. They have Okta. Contractors are defined under different user groups in Okta, e.g. contrator1, contractor2. So ISE will be integrated with Okta and ISE will be authenticating and authorizing the Contractors. Is it possible to pull the user groups from Okta into ISE so that ISE can authorize the users based on group membership, same like how ISE works with AD?