Maybe I misunderstood your question. In AS2005, you can customize the individual roles of a user from Analysis Services. This is where you can define the "granularity" of the users access rights. AD, only authenticates the user, it does not dictate their AS access rights. However, this uses the 'datastore' from Analysis Services (which is separate from Active Directory). The only other way i know to control this is programatically through your own custom application.