Hello Dan, I also have such problem after migration with the "ipa migrate-ds" from the old Freeipa.
Can you explain more how do you fix it? I tried your solution with ldapmodify, but it's not working for me. After removing the attribute and the objectclass and starting kinit admin ipa config-mod --add-sids --enable-sid nothing happened.