sssd 1.6.3 does not resolve group names with spaces (e.g. "Domain Users")
Noticed that this only affects the primary group.
Does it work with other groups than "Domain Users"? I think that Domain Users are kind of a special case where the member attribute is not actually populated. I've tested a group with a space in CN, where CN was my RDN attribute in pure LDAP setting and it seemed to work fine.
It only affects Domain Users. Other groups with spaces are shown correctly.
Upstream ticket: https://fedorahosted.org/sssd/ticket/995
SSSD 1.9.0 beta 1 and later (now in Rawhide) supports ID-mapping of Active Directory.