When using Group Policy to set users.allow (or <pamservice>.allow) sometimes users are fully qualifed and other times not.
There was a behaviour change between 3.3.2, and version 3.5 of the Windows admin tools. Version 3.5 and above will always qualify the groups names after you have added them, 3.3.2 and below will not. If you are using a mixture of 3.5+ and pre-3.5 admin tools, you may see the users.allow change dependent on which admin tools version is used to do the update.
Edit the Group Policy on 3.5, removing and re-adding the users/groups. Avoid editing the policy on pre 3.5 machines.