Windows user is mapped to Unix user and then file access is checked using standard Unix rules. That also answers your second question about groups – at the time permissions are checked NetApp is not even aware that was a Windows user. Group membership is determined using /etc/group, NIS or LDAP, whatever is configured.
You can check tr3490 for overview of multiprotocol access rules.