K, so just checked some old notes and yes, you can modify ipassignment.conf file with groups as sk indicates, as long as they match with what you have on AD side. TAC confirmed this while ago in case we had for a customer.
Btw, below is sk Im referring to:
https://support.checkpoint.com/results/sk/sk33422
Now...WHY enable IA blade? Im sure different people may give you different answers, but personally, here is what I ALWAYS say to people. Its because logs will follow the user no matter where they log in, otherwise, good luck tracking it down by an IP address. And yes, you do have to have IA blade enabled to create access roles, otherwise, policy would never install without it.
Hope that helps.
Best,
Andy