Did you try clear kerberos ticket in the cache by restarting computer ?
When you add or remove user or computer from a AD group , you should clear kerberos ticket in the cache to be taken in account.
Please don't forget to mark helpful answer as accepted