How-to use groups synchronised via SCIM in network firewall policies

In a network firewall policy, how do I refer to Okta groups that I synchronize via SCIM? When I select “user group name” it doesn’t show any of my groups. The only option I see is to use a SAML attribute but that would mean that users would have to re-authenticate every time their group memberships in Okta change.

edit: Actually I just noticed that the UI tries to load the SCIM groups from the API but the requests fail. Is that a bug?

works again