You integrate is as a SAML server and then use SAML authentication type in your VPN profile. As of now, it is limited to authentication only - Authorization requires a separate service (like on-premise RADIUS server such as NPS or ISE) if desired. This requires Firepower 6.7 or higher.