@joshua
Thanks. I've up-voted a few of those open issues.
Since I'm trying to make this work for a COTS application I don't have the luxury of injecting another API call.
For now I'm pretending that the groupId being returned is the LDAP distiguished name for the group (I prefixed it in the Lambda with dn=). Then I can trick the application to looking up the group by the LDAP dn instead of name.