VERY WEIRD! Even though NET USER showed he was in the group. AND the TokenCache showed the group in the list of registry keys, it was returning 0 from InGroup(). Found out he had ZoneAlarm Integrity Client running. We disabled the firewall and ran it again and it worked (e.g. InGroup() returns 1). Weird. Even though the TokenCache shows being in the group, I guess Kix still attempts to do something that ZA blocked in some way?
_________________________
silence is golden, but duct tape is silver