• Have you logged on as Freddag after adding him to the AD group? His token won't include that he is a member of that group until it is regenerated, which is essentially at login.