If you do not configure an ACL for the AD group and assign permission before allowing the AD user to log in, then the SSB will refuse to log you in and record the failure on the SSB internal log.
A successful ACL processing will show the following message:
This message will show when an ACL exists
2022-11-15T16:14:54-05:00 epssb02 ssb/web: INFO (email@example.com
) Authentication succeeded; username='aduser1', groups='Administrators, Domain Users'