You can use AD groups for AD access control and section access authorization. Use NTUSER authorization in section access and use the group name (for example AcmeDom\QVUsers).
You will need individual licenses though. Named CALs cannot be assigned to an AD group, so if you are using Named CALs, you will still need to assign them to individuals
Logic will get you from a to b. Imagination will take you everywhere. - A Einstein