Currently for AD joined machines, only AD group membership is synced. Most clients have AD sync to Azure and management is done primarily in Azure, so would be good to have Azure group membership synced as well.