Is good access control really a matter of well-managed groups in AD?

Good access control requires you to catalog your resources, identify the best person to decide who should have access to each resource, and automate the approval and periodic review process.


But at the end of the day, good access control comes down to avoiding the use of local groups (whether on Windows file servers, in Microsoft SQL Server, in SharePoint, or elsewhere) and instead assigning permissions to Active Directory (AD) groups.


