Again...my sincere thanks to everyone who responded to this post.

Quote:


Oh, and you didn't tell us what was listed in the Token cache. Was the group in question listed there? Was the group in question renamed? Do other groups work or do all global groups fail? Is the group name long?





These were wrong. They were showing some, but not all of the correct groups (no new ones).

Quote:

Is your GC healthy?
Try to include the domain name with the groupname.




Nope. I took a look at the GC settings on my domain controllers and noticed that the GC checkbox was unchecked on the domain controller with the FSMO roles.

I checked the box and ran my production logon script. The TokenCache registry entry immediately filled up with the appropriate groups. And the original script ran just fine.

Not sure how that happened. We haven't had any major changes to our domain lately aside from some new employees. It only really showed up when we started this project to roll out a piece of software based on group membership.

Thanks so much everybody!