You still need to be careful that you don't unintentionally grant all servers access to all data through LocalDomainServers or some other group, so test carefully after rolling out such a model.
Our test exercises the PERM_ENTER permission; additional permissions are included to illustrate how AllPermissions needs to enumerate every permission that EAz requires to grant or deny authorization.