I'm new to this, but here's my 2 cents. In a active directory environment, I was using the
IF INGROUP ...
use *
and it was not recognizing my groups. changing the group from global security to local domain fixed the problem.