Recently we had several similar questions in internal discussions and community about scenario where users should be disabled based on their membership in specific group. While it's quite easy to check membership in user-to-user sync, we also could try to do the same with group-to-group sync by using new feature.
In this case we need group-to-group update step with rule like on screenshot below and we even don't need users to be mapped.
Now we can check results.
While using this feature you need to be cautious because it allows updating objects out of connection's scope!