What I found by adding debug_level=7 to the sssd.conf file was this cryptic message:
Trying to resolve service 'AD_GC'
I realized at some point I was firewall'd off to the Active Directory Global Catalog port 3286, once I opened this I can now get the correct groups mapped to my SSSD users.