Just because you can tie NTFS security to security groups doesn't mean you have to. You could also deploy GPO logon scripts instead of legacy scripts.
_________________________
Give a man a fish and he will be back for more. Slap him with a fish and he will go away forever.