Hi,
the attached patches should fix https://fedorahosted.org/sssd/ticket/2027, i.e. always show that and AD user is a member of it's primary AD group, even for subdomains.
The first patch in this series just fixes a typo I came across while working at #2027.
bye, Sumit