SGTs are usable where Trust Sec is deployed, the question simply asks about a better way of handling ACLs, substitute for Static ACLs should be Dynamic ACLs configured on ISE Authorisation Profiles. https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212419-configure- per-user-dynamic-access-contro.html