Did you know you can disable import of AD roles via the web.config application setting: <add key="CMSImportWindowsRoles" value="false" />
I believe this will give you more control over user management. It will also improve the performance of the application. Good luck!