I've been an admin for a few years now, but I don't remember this happening. I can create a group in AD, assign some users to it and then give the group permissions to a folder (any folder, local to the user -or- on the server). The users aren't able to access the folder for an amount of time (haven't timed it exactly). Later they can access it fine. If I go back in later and remove a user from the group, they can still access the folder for another length of time before it restricts them. If I apply the permissions on a per-user basis, there is no time delay. On the two other networks I'm administered, there was no time delay for group membership changes. I assume it has something to do with AD and replaction, but I don't recall ever learning anything about it affecting a domain that has only one site, two servers.
Spencer
MCSE2k, MCSA2k, Net+, A+
Spencer
MCSE2k, MCSA2k, Net+, A+