There is an issue that creeps up occasionally like this:
You add a user to a SharePoint group with some privilege, let's say
contributor. You then assign an AD Group containing that user, with
lesser permissions like Read, directly to a permission level. What we
are seeing (haven't nailed this down as to when/why) is that the AD
Group will override the user permissions, and they end up with Read, in
this example.
Now that I read this thread, it is possible that it depends HOW the
permissions to the user/group are applied. i.e. AD Group into SharePoint
Group vs. AD Group to Permission Level vs. User to Permission Level vs.
Users to SharePoint Group.
I don't have the answer, but I wanted to let you guys know there are
some issues as above. Todd Bleeker found this originally, but I don't
know if he has the exact circumstance documented that makes this happen.
I will try and track this down this week.