When I was in lower tier support (and sometimes still), one of the most annoying sequences of events was a request for new file permissions >> add user to security group and specify in the reply "you must log out and back into your machine". 20 minutes later, "I'M STILL GETTING DENIED PERMISSION!!". Because you didn't log out and back in did you
Why don't Windows machines in an AD domain periodically query and update the user group membership like they do for group policies and many other things?