I'm looking to replace my CDA with ISE for transparent user auth for our WSA. The thing that I'm seeing is when I want to add users and groups to an access policy, I cannot add AD Groups like I can with the CDA setup. I can only use SGT's. That's fi...