A system and method are provided for managing mobile user access to enterprise network resources from a wireless mobile device, such as a smart phone or mobile computer, with improved security and access control. Access rules determining accessible resources and associated permitted operations are determined based on membership of an authenticated user to each of one or more groups, each group being associated with a set of permitted accessible resources and operations. For each user, based on membership of a group, or a Boolean evaluation of memberships of two or more groups, a list of accessible resources and permitted operations is generated, and the list is made available for subsequent processes, e.g. presentation to the user on an interface of the mobile device. Access rules may also be defined dependent on other information received from the system, or from the mobile device, such as time or location. Requests for an operation such as read access or write access to a network resource, such as a file, lists, shared calendars et al., may thus be readily controlled by an IT manager for multiple users of an enterprise network. Since the application resides in an application layer between the mobile device and existing security infrastructure, mobile access may be set without overriding internal access policies.