Individual user authentication via Active Directory

The ability for Filemaker to use Active Directory for authentication is awesome, amd works great for me when I'm using an AD group. However, is there a way to have/allow individual users to authenticate and have privs unique to that user? Do I need to make an AD Group with only that one user in it so I can have a Filemaker Privilege set matched to that user?


And lastly, I'm guessing if a user is in multiple AD groups, the one which is listed first on the "Accounts" screen is the one the user will be authenticated by, correct?