Hi,
yes, this can definately be achieved using AD as the identity store.
In the access service processing the wireless 802.1x authentications, include the compound condition or AD1 external group condition using the customized button on the right bottom corner.(bring the condition from available to selected portion).
Now, go to the rule responsible to process the authentication process, or create a new rule and call out the group(s) for which you want the authentication to pass and at the bottom on the default rule select deny access authorization profile as a resultant.
Let me know if you get stuck somewhere.
Thanks,
Prateek