Might help to use global group/local group with a trust (in the right direction).

add GG to LG on that resource, and use the trust to authenticate. Use NET USE to map drive without extra authentication...