Suppose you want to limit access to some servers, only people member of a specific group (or multiple groups) may log in.
The following is one way to tackle this. In this example I will
configure ssh access in such a way that only people from the
admin group can login. The nice thing is that this will work
regardless of any Kerberos or LDAP usage.
Preparation
In /etc/pam.d find the “service” which you want to add a group
policy to. For instance sshd, edit that file (this is with Ubuntu):

