Research led me to these pages:
http://support.microsoft.com/kb/103390
http://technet.microsoft.com/en-us/l.../cc749912.aspx
http://www.microsoft.com/windowsserv.../security.mspx
which all seem to be written for the use in a domain environment, rather than a workgroup. I would expect the same design philosophy to be used, with different fallbacks (workgroup would presume automatic fails in contacting a domain, for example). I haven't been thru the W2k3 document yet, as the details in the KB pages are a bit dense for my background. It is educational

A lot of things seem to be coming back to KB103390, so that seems to be something central to understanding what's going on.