I think I have understood what are asking! When not then I am sure you will let me know!
We have Groups in AD and obviously These Groups are populated with AD Users and/or other Groups. These Groups are added to the SQL Server instance and roles and permissions assigned in exactly the same way as a normal AD user.
From within AD itself is nothing Special required. The Groups Need to be created of course but no Special permissions Need to be granted.
This is a Scenario that we have in our Company and it works very well, is extremely simple to administer and provides excellent oversight where several databases exist in the same instance.
I hope that helped.....