USE master
CREATE LOGIN [$(UserName)] FROM WINDOWS WITH DEFAULT_DATABASE=[$(DatabaseName)] GO USE [$(DatabaseName)] GO CREATE USER [$(UserName)] FOR LOGIN [$(UserName)] GO EXEC sp_addrolemember N'$(RoleName)', N'$(UserName)' GO
USE master
CREATE LOGIN [$(UserName)] FROM WINDOWS WITH DEFAULT_DATABASE=[$(DatabaseName)] GO USE [$(DatabaseName)] GO CREATE USER [$(UserName)] FOR LOGIN [$(UserName)] GO EXEC sp_addrolemember N'$(RoleName)', N'$(UserName)' GO
For any login in an NT group, if you want to reduce, or increase more permissions, just add the login by itself. The individual’s permissions wins.