I investigated one day, that I can't add some specific user to any group of some specific collection, I can add them directly to list/library/page only. For example "Xavier Xovi" can't be member of any group of Marketing, but his account can be added to Technology, Sales or Home coll. "Daniel Donn" can't be member of Sales, but his account can be added to Marketing, Home and so on.
I have 6 problematic users right now, all works under old MOSS 2007 portal without problems, even on testing 2010 farm without problems, but fails on product farm. No error message, no on-screen warning, I just get blank group page without my user. Nothing new in event log, ULS logs, users are properly synchronized with AD and they are members of group in another groups, but groups for each of them cannot be more then 4. Any idea whats happening?
[edit #1, 05. 11. 2011] I can see them in groups thru Designer, they are already added. But even if I am owner of the group, SC Admin, Farm Admin and lord of all, I can't see them via classic portal UI.
[edit #2, 05. 11. 2011] The clue is in User Information List in affected SCs, where users completely missing and cannot be added or migrated. If I click on user name in page footer (Created at... or Last modified at...) I can see only error page, because links headings to wrong user ID. Search works, My Site works. When I open another SC and its UIL, users are there and links properly heading to their My Site profile page. No, I can't delete them, they are owners of a huge number of files.
[edit #3, 16. 03. 2012] Problem was open as issue in Microsoft support and the clue is definitely in user list (userdisp.aspx page). The page is buggy, sometimes cannot be render (Render fail error in an attempt to show name filters) and even paging sometimes missing.The only question is whether it is caused by migration tool or not (and how to solve it). Captured correlation ID is not in any log and developer dasboard shows nothing. The userdisp.aspx file from product enviroment is very similar to testing one, there is just one exception in SharePoint:DelegateControl Scope atribute. Testing farm (where everything works properly) has Scope set to "Farm", product farm to "Web", but change did not bring any solution.
[edit #4, 10. 04. 2012] Our nearly one year issue has solution, see answer below please. We tested MS solution this weekend and we are little embarrassed. We ran content deployement job three times, each try ended with different result but third try was quite good... Permission works, even a lot of things, that none of migration tools can deploy correctly was there (like CEWP above the list, color overlays, quick launch menu, list highlighting feature and so on), but there is also a huge number of small things, that must be manually corrected after deploy like home pages, system account at all folders in all libraries or web patrs in pages at all. So, we must decided what is better for us, permission issue or another small "migration" for next 9 or 10 weekends...
See resolution from Microsoft below please and if you have another idea how to fix it, write it down please.