We have an instance of Jira Server that is configured to use our LDAP server (ORM LDAP Server) for authentication as shown below:

In addition to this, the Jira instance is also used to provide authentication for a Confluence instance.
This works perfectly well, but there's a behaviour that we would like to change. As configured, our LDAP group information is copied to the Jira instance and allows us to add users to both the locally created groups and to those groups that are copied from the LDAP server. The information copied to the groups supplied via LDAP is not synchronised with the group information in the LDAP repository. Having the ability to augment the group structure with new, local groups is a requirement, but we don't want to allow those groups that are synchronized from the LDAP server to be modified locally. We would prefer that the groups supplied via LDAP are managed only via the LDAP server and not via the Jira UI.
Is there a way that this could be implemented?