Orrison,
Based on my experience and the information that I have the admins should exist in checkpoint management server database. You can't authenticate using a user doesn't exist in checkpoint database to smart console.
you can authenticate checkpoint admin exist in checkpoint database using radius that would work.
Authentication using domain users might be possible for Smart endpoint manager but but not for the firewalls management server.
I didn't see any change in the documentation. In order to troubleshoot you have to debug FWM process on the management server, you might need to debug cpm too but not sure.
Thanks