Role-based Active Directory groups are a convenient way of connecting AD objects to Aternity roles. Unfortunately, the Aternity server has a refresh period of 12 hours. If a user needs access to Aternity, I add them to the AD group and have to wait 12 hours. Alternatively, I grant support levels 1, 2, and 3 the ability to modify Aternity settings so that they can click the "Refresh Cache" button in Settings --> Enterprise Environment Integration --> Directory Service. Obviously, this is not ideal.