Why not "Bind" the Computer to your OD domain server? Then you only have to maintain the groups in one place. The OS will do the authentication and you don't have to make any local groups and people assignments on the FMS computer.
Generally it goes like this:
Open the System Preference.
Select User's and Groups
Select Login Options
- At bottom of right side of panel should be the "Network Account Server:"
- a New window will slide down
Select Open Directory Utility
- This app is what we need. If you can find this utility app another way you might get to it faster.
Edit the "LDAPv3" service
Add your OD Domain server and authenticate with a Domain administrator account.
Click OK on all the windows to get back out of the set up.
Apple provides better instructions than I do so I suggest looking into their knowledge base.
I'm aware of Binding, but we choose not to as a company. There's no real need for it for us. The main purpose of posting this was to put the information out there for anyone else who might have, or will, run into the same problem. Just thought it odd that FMS 11 behaved differently than FMS 10 with regard to the external authentication groups within the DB file.