To integrate the vCenter VCSA appliance with Microsoft Active Directory as the identity source opens up a way for vSphere administrators to be able to use a common identity source to grant access to vSphere objects as they do file servers and any other resource on the network which centralizes this process. Centralized and simple is the best strategy here for administering permissions.