I want AD groups to have dynamic membership depending on a user having a resource, their domain and a custom field. The only way I can see to do this is to create a business role for each group and apply dynamic membership to that business role so that the user inherits the AD group. Is there a better way to do this?