Followup - Problem Resolved
At it turns out, Splunk was working as advertised. The problem observed was the result of two different configurations interacting in an unexpected way.
The user in question had been granted access to the index in question via a Splunk Group that had only granted access (but not set the index as a "default search") The group that was supposed to grant access and set the index as default was not being used since its corresponding Active Directory group was empty.
Under the assumption that the specific group was working correctly, the only explanation was that there was a Splunk bug with how the SrchIndexesDefault variable was being combined for the user.
Once I discovered that the user was being given access to the index through a group that did not set the SrchIndexesDefault variable, the pieces fell into place.
I rectified the config and test, and Splunk worked correctly.
... View more