I want to audit database object access events (DATABASE_OBJECT_ACCESS_GROUP) for all members of a specific Windows AD Group which has been added as a login in SQL Server. Should this be done in the Audit or in the Server Audit Spec? I cannot audit by individual AD Account because the members of the AD Groups changes over time. Any ideas on how to implement?