Hi,
if i read your post correct, you have a vCenter Server right? If so, why are you not creating a Rule in vCenter and assign the needed permissions to that group.
After that, you could map a AD Group or User to that Rule and add it to the VM´s that you wan´t to share.
Frank