If you do not want to use the built-in roles with the pre-assigned privileges, you can create custom roles where you select specific privileges and assign them to the Active directory groups.
For example, you can create a role that gives privileges to perform all actions on Writable Volumes (such as create, activate, deactivate, rescan, and so on) and also view the online directory of users. You can edit the privileges later and the updated privileges is dynamically allocated to the members of the assigned group. That is, the members do not have to log out and log in to the system to get the new privileges.