I had posted on this topic, Security and Active Directory, recently – but wanted to raise it again. The important concept here is that who you log into GP as – no longer matters. Security is driven by who you log into windows as.
The rest is here:
SmartConnect and AD