Ok, for a while now I wanted to be able to scope policies based on AD
Group membership. While building out policies I noticed, this can only
be done during login/logout. Finding this out was kinda frustrating, so
I decided I was going to come up with...