Assign entitlements assigned to department to employees with exception

I have AD groups assigned to Department with inheritance - how to assign this groups only to employees in this department which meet the condition?