Vipal, did you ever find a solution to this? We're on AEM 6.2 and are having the same issue. Once a user authenticates, he's added to AEM from LDAP and belongs to xyz AEM groups, which also came from LDAP. But if I update the user and add him to a group, and then login again as that user (or sync...