The difference is I have to know the user ahead of time if I want to configure it before it goes out. I don't usually have that information for a new remote user. Sometimes when the PC is requested, they aren't even hired yet.

The other method is dynamic. I understand that the security (or lack thereof) is the same.

And the only reason it matters to me that they are removed later is so I don't have more than one user in the admins group.