Scurity Policies based on Radius VSA not working on PA-220

I configured FreeRadius server to reply to PA-220 two VSA in a VPN Global Protect connection:
Framed-IP-Address = 10.0.154.x
PaloAlto-User-Group = "operators"
All ok for the IP address. Clients take the replied ip address.
I don't understand how can use PaloAlto-User-Group to create policies based on its value.
In this way I could define rules based on users' groups.

I noticed that at level of authentication profiles the user-group is recognized and considered but not at level of security policies' rules.

I don't use LDAP server, my users are in FreeRadius DB.
Any suggestions ?
Thank you.

