In SCCM 2007 AD Security Group Discovery, it's called "Include Nested Groups" which if you don't check that box, only the security group objects are discovered and none of the nested group memberships (User or computer objects) are created...plus
it didn't matter whether it was a Security type or a Distribution type security group...it simply didn't create the membership objects. In SCCM 2012 AD Group Discovery, the setting is called "Discover the membership of distribution groups" but even
when you don't check that box, AD Group Discovery still creates user and computer objects for the nested members of security type
groups. I am still hoping I just missed something and I can still prevent AD Group Discovery from creating membership objects in
security type groups.