Sorry, I didn't see a request to test. I have over 800 workstations and only some have this problem. My test machines work fine with Domain User accounts (with the /f switch). I originally thought this had something to do with us "ghosting" machines, so the SID in the cache didn't machine the SID on the new machines, but my most recent results contradict that. Won't be getting around to test any time soon.

Anyway, the this thread seems to tell me that this function is problematic and should be avoided, unless someone has some work around I haven't seen yet, or I'm misunderstanding.