We're trying to use AD group membership as part of authentication rules for the TACACS+ policy sets. However, while we can write such a rule (<our AD>:ExternalGroups EQUALS <AD group>), it immediately replaces the AD group name with the SID, and the ...