If your rule definition includes AD groups, we recommend that you:
- Put all of the individual local and AD user permissions first. The order of the individual users does not matter as long as the entries are unique.
- Put all of the AD group permissions after the individual users, making sure that you have the correct order of precedence so that users are not being granted permission to access data they should not access or being denied permission to access data they need.
- Make sure you allow access to the smallest AD groups possible. For example, if you have a group that includes all the developers in your company and smaller sub-groups that are specific to each product line, try to use the product-specific groups unless everyone in development truly needs access to the data.