After checking, I confirmed that users are direct members of this group and the users are part of the AD tree.
Also another things that I discovered here: it’s not possible to filter users using memberof
and after trying to use a filter to search one user to be synced the error is showed in var/log/web.log:
cmk.gui.plugins.userdb.ldap_connector.MKLDAPException: The "Authentication Expiration" attribute (pwdlastset) could not be fetched from the LDAP server for user
Any other clues that we can test here @andreas-doehler ?