Symptoms
Process Rights for groups not working
Diagnoses
1. To check if these groups contains the user having the issue, please execute the Smartobject Service Tester Tool > All Smartobjects > UMUser Smartobject > Get Group Users method. Specify the Group name in the format 'DOMAINGroupName' with the 'LabelName = K2'. Does this return the correct users belonging to this AD group?
2. If using nested AD groups, one can add all of the nested groups or perhaps enable the "Resolve Nested Groups" feature as per:
http://help.k2.com/onlinehelp/k2blackpearl/userguide/current/webframe.html_k2_um_settings.html
After enabling the "Resolve Nested Groups", a K2 blackpearl service/console mode restart is necessary.
3. If there was a 'membership' change in AD, it can take up to at least 1 hrs before this group's membership is expired and re-cached within K2's Identity Service:
http://help.k2.com/onlinehelp/k2blackpearl/ICG/current/webframe.html_Tweaking_identity_cache_performance_for_the_K2_Server.html
Once can force the expiration and re-caching using the 'Smartobject Service Tester Tool > UM Smartobjects' and the 'Identity Service Refresh Tool' below:
http://community.k2.com/t5/General-K2-Utilities/Force-Identity-Service-Refresh/ba-p/74061
4. If applicable, one possible workaround for the time being is to add the K2 "Everyone" group and grant this group Start right usually this group can be found searching against the 'K2' label with the 'everyone' string (lowercase e). This is a K2 group that behaves similarly to Active Directory's "Domain Users" group.
Resolution
The issue was resolved with one of the suggested steps.