UiPath Cloud Platform - AD Groups

just wanted to confirm if it’s possible to do the following.

I’ve created a user account in the Cloud Platform;

  1. Is it possible to prevent the user from using their UiPath username and password to authenticate when logging into my instance (https://platform.uipath.com/xxx), and force them to login with SSO by selecting ‘Microsoft Account’, this will ensure that they use their corporate account/password and we can enforce our corporate authentication policy (MFA)

  2. Are we able synchronize group membership (automatically when a user logs in) to user roles in UiPath Cloud Platform based on specified AD groups that the user is already a member of on the corporate network via the SSO option above? I heard this was possible, but can’t find any documentation on the topic.