Can I map multiple AD groups to multiple roles on ESXi?

I have an AD joined ESXi server (v7.0) without a vCenter server. I can map an AD group to the "Administrator" role by configuring the advanced setting Config.HostAgent.Plugins.Hostsvc.EsxAdminsGroup. But is that all? Can I not map an AD group to the "Read only" role, for example?

You can map groups to roles via the following path in vSphere Web Client:

  1. Right-click on Host or on Manage
  2. Click on Permissions

