Miami prefers group and role-based schemes which support coarse and fine-grained authorization privileges. Group and role attributes should come from an appropriate Miami directory service. Applications may provide group and role management if such attributes can be managed via Account Provisioning.