Active Roles 7.4.4 Capabilities

Hi,

We are looking to automate our current joiners, movers and leavers process and believe that this can be achieved using the latest version of AR. 

We would like to setup AR integration with ServiceNow and then create the following workflows in its simplest form:

New User

1. SNOW - New User Request

2. Active Roles - create user in our on-premise AD and add to default groups

3. Active Roles - add user to O365 and AAD groups directly (not sourced/synced from on-premise)

Department Move

1. SNOW - Dept move request

2. Active Roles - Update user in on-premise AD, add and remove groups from on-premise AD

3.  Active Roles - add/remove user to O365 and AAD groups directly (not sourced/synced from on-premise)

Leavers Form

1. SNOW - Leavers request

2. Active Roles -  User deactivation and group removals from on-premise AD

3. Active Roles - Remove user from O365/AAD groups

4. Active Roles - Convert to shared mailbox 

The previous version of AR wasn't able to write directly to O365/AAD groups but my understanding is that this is possible with version 7.4.4. 

Does anyone have something similar setup and how difficult is this to implement?

Thanks in advance.