We have a few groups in the LDAP directory that tracks our developer accounts that have historically been used in Gerrit as part of the authorization for various repos. Specifically, the ops LDAP group is granted ownership on operations/puppet.git. The wmf LDAP group is also used to confer membership in the mediawiki gerrit group which grants a large number of rights on mediawiki/* repos in Gerrit.
LDAP group sync is a premium GitLab feature which means it is not available in the FOSS GitLab CE product. We also are not directly using LDAP for authentication, so it may not be a useful feature even if we broke from using the FOSS product.
It seems reasonably possible to write a bot that knows how to talk to both GitLab and LDAP with configuration telling it which LDAP group memberships should grant GitLab group permissions.
This feature request was inspired by a short irc discussion with @Joe related to the membership of the repos/sre group.