Here's what I understood of that: The problem was how the group that was
supposed to give me access was set up in AD a long time ago.  Apparently
when you have an AD forest or a federation you can separately flag if
the groups are visible or valid outside the defining domain and it had
been set up to have restricted validity, while still being visible in
all domains.  Only when both these flags are set will the group actually
be in your AuthZ token ("universal group").  Actual file access still
worked since the access was checked on the file server which was in the
"home" domain.  So, the group got converted to a universal one and the
problem went away after that change had replicated to all DC.

