I've just started playing around with the enableARD.sh script here:
https://jamfnation.jamfsoftware.com/viewProductFile.html?id=12&fid=217
I'm running it for an AD group instead of a specific user though. After running the script, If i check Directory Utility i can see the GeneratedUID of the AD group listed in the value of the NestedGroups attribute. But if i look under System Preferences > Sharing > Remote Management, I don't see it in the allowed access users list.
Is that to be expected? Or is something else needed to get an AD group (as opposed to a remote or local user) to display?