If I understood correcly, you have to create manually with EXT_ID_ prefix.
if your grp attribute is "akos", then you need to create an user group with EXT_ID_akos name:
In SmartConsole, create an internal User Group object with this name (case-sensitive, spaces not supported):
For example, for a role in the Identity Provider's interface with the name , create an internal User Group object in SmartConsole with the name
Note - In Microsoft Azure, Identity Tags are not supported for Remote Access connections.
I hope it helps