Azure Active Directory limits the number of groups it will emit in a token to 150 for SAML assertions, and 200 for JWT to prevent tokens getting too large. If a user is a member of a larger number of groups than the limit, the groups are emitted and a link to the Graph endpoint to obtain group information.
This request is to improve the current SAML SSO integration to allow artifactory to consume the graph endpoint. In large organizations, SAML tokens can exceed HTTP header limits which can can lead to unpredictable results. Thus, Azure will emit a graph group claim to allow the app (artifactory) to query all groups the user belongs to.