Hi Robert,
The proposed scenario is better if compared to current one in terms of user management. With the proposed approach there will be no need to perform any activity in CMC once the user is added to their respective AD group. You just need to have User update job scheduled periodically.
Thanks,
Shwetabh