Just as ARM is able to provide Fileserver/Exchange/Sharepoint/... permissions it would be great if it would be able to provide permissions on AD Objects (eg. Delegated Rights).
Our end customer has to be compliant with Germans' KRITIS regulation for critical infrastructure. Therefore, all permission changes have to be documented in a way like ARM does provide it (leave a comment).
At the moment the customer is forced to use AD onboard resources.
Thank you very much and kind regards,
Emanuel