We have 2 AD groups. The first with view permissions and the second with edit permissions. A user logged in for the first time and was in both AD groups. He received only view permissions. To fix his permissions, I had to delete the view group and his account from VisualCron. Then next time he logged in, he got the edit permissions. It would be nice to have VisualCron do the union of permissions. Failing that, VisualCron should allow you to pick which AD group to use.
New users are inheriting the default permissions for the AD group. If user belongs to many VC permission groups he will use the highest permission available.
