A resposta a esta pergunta foi respondida em outro fórum.
The LDAP filter to list all groups (included nested groups) of a user is:
(member:1.2.840.113556.1.4.1941:=
So for example: (member:1.2.840.113556.1.4.1941:=CN=Alice,OU=Accounts,DC=contoso,DC=com)
Now how does it translate into a claim rule and ultimately a claim... First of all, I create 2 claim definitions. One called UserDN with the id http://contoso.com/myclaims/UserDN and MemberOfDN with the id http://contoso.com/myclaims/MemberOfDN. You guessed that the first one will receive the DN of the user and the second all the DN of al members the user is a member of.
O artigo completo pode ser encontrado aqui: responder .