It comes up all the time when I want to know if anything in AD is not listed in CM and has a client, etc. If you work for an organization that is blessed with having excellent asset management, you could compare CM directly against your CMDB. But, everyone is not this blessed as it turns out. And reality being, you really should compare everything in AD to everything in CM. If its a domain joined computer, you'll probably want to know if it is or is not being managed by CM.
Often I get access requests, especially for new employees, for setting up someone’s network permissions like Dan's in the marketing department. Dan is new to the Marketing team and his manager wants his account set up like Paul's account. So, normally, I would do a side by side comparison in ADUC and then fill in the gaps. That sounds a little tedious. So, I wrote a quick function to compare groups and output those that are common between each and unique to each. Here is a sample of the output from the function: