Hello @HalynaK2 ,
You can use OOTB SAML2.0 Authentication Service. In the configuration, you can configure a Post Authentication Activity and write the logic to assign access group(s) dynamically based on the data received from IdP.
In Constellation, the best practice is to provide your user with a unique Persona (Access Group) for each of their applications. There is also no option to switch between multiple access groups/portals for each application as of now from end user portals. You can only switch across different applications. You can find more details about this in the below article by @MarcCheong