tariqf,
Please let us know your findings. It's hard to say if you can replace the actual service according to your staff. In ISA you restrict access using Active Directory and that propagates throughout your domain/subdomain (making things a lot easier). In SME I'm not sure how to control this, or if it's capable of such task, since the control is done on the server (locally). Two SME will act independently.
Correct me if I'm wrong.