I believe I am dealing with a knowledge gap. I think I understand this about 80% but apparently that is not enough. Questions like this have plagued me for a long time. I will try to be a clear as possible. Server OS Windows 2003 R2 Standard SP2. Desktop OS Windows 7 Pro SP1 and some Windows XP Pro SP3.
So I have a domain called DOM1. In the domain I have a user named Ralph. Ralph is in the Domain Admins group and the Domain Users group. I have a workstation named MY-WS. This workstation is part of the DOM1 domain. I am logged into MY-WS as Dom1\Ralph. I have added the DOM1 Domain Admins group to the builtin Administrators group on MY-WS. For the time being, I don't care about any local users or groups on MY-WS. I create a folder on the desktop (don't think it matters where) and remove inheritance and remove all but the Local Administrators group from the Security tab and confirm that the Local Administrators group has Full Control permissions on that folder. I can do the same thing with the Sharing tab with similar results.
That's pretty much all I need to ask my questions. My understanding is that any user in the local Administrators group has unlimited control of that workstation. I also thought that if a user was a member of a group, then adding the group was the same as adding the user. Not sure if it has anything to do with Domain vs. Local groups and users. When I try to open the folder I get the following popup (image 1). You don't currently have permission to access this folder. click continue to permanently get access to this folder. If I reply Cancel, nothing happens and I cannot access the folder. If I reply Continue, I get access to the folder and when I check the Security tab on the folder again, DOM1\Ralph has been added with Full Control. That's the part I don't understand. I was always told to use groups and not users for things like this, so if the people change or you want to add or remove access for individuals it is much less of a logistical nightmare.
There are many other examples like this, but I have a feeling that when one of you more learned people read this you will go "Ohhhhhh, Yeah, Of course it does and this is why". Anyway, thought I would give this a shot. Thanks a bunch in advance for your help and cooperation.