Windows authentication with roles?

What would be the best way to create an intranet application that uses roles to stop users from accessing certain parts of the website based on roles?

I read that active directory groups can be used for this but I don’t know if I have access to create these “groups” or know anything about active directory. I wanted to allow the application users who may be admins to manage permissions via the application. Can they also manage active directory or is that usually reserved for someone working in IT?

