I work with Steve Curry, who started this thread. We eventually made the AD provider work in 4.06.00 and then upgraded to 4.08.04 and everything went along smoothly for about 2 weeks. Then the problem came back. The problem being that when an AD user logged into DNN they were stripped out of all the security roles that they were part of. We are now on 4.8.4 and AD Provider 1.00.04.
After several days of troubleshooting I reread this thread and noticed the post of Universal groups working and global groups failing. I switched the group types in our AD structure and instantly the sync started to work again. There have been no changes to our AD over the last few months since we fixed the initial problem which seemed to be related to a custom login module that had been built to catch the <enter> key and not send the user to the search screen instead of logining them into DNN.
If there is a way to fix this please let us know. Mostly just posting to let you know that others have the same group type issue.
Thanks,
Richard