I have the same issue, though I've discovered the following: If I create a local group 'fmsadmin' and create local users and add them to that group, it works fine. Domain users added to that group do not work.
My suspicion is that this is a SPN record issue. For kerberos to work, if a server is trying to do passthrough authentication, an SPN record for the service is usually required.