We are wrestling with a design for using Security Groups in AAD to drive access to Dynamics. We know the mechanics, but wondered if anyone had done this successfully and could share any insight. I have attached what I hope is a brief spec...any discussion, hints, gotchas, resources would be much appreciated.