Yes you can will create a authorization profile under you policy elements which will contain the "need to know rule", then you will retrieve the group in your ldap settings, directory attributes and select the group after you search for it.
Finally create a access policy, that will contain the authorization profile, the ldap container. Keep in mind you will have to customize this option to active the policy elements you wish to map.
Thanks,
Tarik