Hello,
Are those "LDAP Account Units" assigned to the same GW or different GW's ?
We have 3 "LDAP Account Units" per each domain in our infrastructure, and those are assigned to a cluster out of the 3 we have , and we don't have any problem with AD Group mapping for users.
(so it's an one-to-one map LDAP Account Units to GW )
when we create an Identity based on AD group, or user, we do the LDAP mapping three times, addressing each "LDAP Account Units" that we have for that specific domain, so in your case, you should MAP the AD group based on a search done with LDAP AU A and with the LDAP AU B (hopefully you'll get it, otherwise I'll get screenshots....)
Thank you,
PS: if I didn't understood it correctly, please provide more details