Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I may be wrong but I think that AzureAD integration to sync users and groups is only leveraged for the SAML SSO auth into Umbrella? I am not sure if it is meant as a replacement for what the on-prem AD connector does for policy.