Workaround 1: Create an OU within the root of the Active Directory domain ("people" for example) and then move the users that will be authenticating to ArcGIS Server services into that OU. Then create an OU within the root of the Active Directory domain ("roles" for example) and use the workflow outline in the following web-help to re-configure ArcGIS Server security to reference these specialized OUs: http://webhelp.esri.com/arcgisserver/9.3.1/java/configuring_security.htmWorkaround 2: Use ArcGIS Server .NET / Windows Users & Groups Security