If you have a provider that is configured to return the groups a user is a member of, this setting is provided to accommodate non-standard implementations.
Major providers (Okta, Auth0, Salesforce, AzureAD) return the user's group membership in a JSON property named "groups" which is the default.
Default: "groups"
There can be other implementations where other names may be used such as "roles".
The best way to understand your provider's returned information if not one of the providers listed above, is to turn-on OAuth2 OpenID Detailed Logging, have a user sign-in and then check the OIDCAuth.log file found in the FVTerm Internal Logging Root Folder.