You can use the groupsync subcommand to synchronize groups between Active Directory and Directory Server.
To enable or disable the Group Synchronization, type idsync groupsync command.
For example:
idsync groupsync -{e/d} -D <bind DN> -w <bind password> [-h <CD hostname>] 
[-p <CD port no>] -s <rootsuffix> [-Z] -q <configuration password> -t <AD group type>
Table A–9  groupsync arguments| Argument | Meaning | 
|---|---|
| -{e/d} | Select e for enabling , and d for disabling the group synchronization. | 
| -t | Specifies the group type at Active Directory. For example, it can be selected as either of "distribution" or "security" |