Tech Services engineers are investigating a possible issue with group syncing between AuthMan and the UOFI AD. This does not impact Azure AD syncing or API queries.
Some access policy groups may not be updated in LDAP in a timely manner, causing user membership to be incorrect. This only affects groups in the default OU=AuthMan container in the UOFI AD. Custom provisioners are not affected.