Personally for me I think that it's potentially opening up the platform and would become an additional security risk to consider. Obviously the level of risk would be dependant on how secure the Active Directory is.
Generally it would allow for anybody say with domain administrator access to be able to grant themselves access firewall management. Unless delegation was put in place over the AD groups. But on the other hand it would be a great way to manage access. Of the active directory was ever to be compromised this would then also put your firewall platform at risk also.
Having the permissions controlled by the SMS rather than AD is a lot more secure and would reduce the risk.
If it was available it would be a matter of weighing up the risk with the benefit.
Maybe if it ever does become available then delegating access to the as group that controls access to the firewall would become a best practice.
Those are my thoughts.