OK this is getting frustrating!
I amended the Differential Person Query to match the normal person query… Removing the person from the ecms_users group results in them being removed from Alfresco. Great… BUT, when re-adding that user back into the ecms_users group in AD, on the next differential sync, I get
Ignoring non-existent member 'xxxx' in groups {'ecms_users'}
Why is it not re-adding this user back into Alfresco? It knows its part of the correct group, but wont create the user again?
Can anyone tell me whats going on and how we can successfully control user creation and deletion from an AD security group properly?