CN=GLB-xxxxxx shows up under thier authorization in the failure message and that's what we key off of. Only difference between this user and me is that in the authorization on the logs the group shows up under Group and memberOf.
Have tried keying his off memberOf or Group and it does not matter, he just does not match..
Rule is Authsource-AD, meberOf, equals, GLB-xxxxxx