I'm largely using default settings with the exception of User Extinction Handling which is set to remove, screenshot attached. If I use the browse button next to Distinguished Name I can see and select the OU's, so ESMC can access and read the groups from AD.