SailPoint has released their own “loopback” SaaS connector that you can use
You can alternatively use the CoLab SaaS connector that some people prefere
If you want to “link” them to an AD group, you can then create a role that detects users who are members of a specific AD group and assign them the desired ISC user level, but this seems unnecessary with the existence of the above mentioned connectors