Thank you for posting this in Microsoft Q&A.
As I understand you have done user migration from one forest to another forest. Now, everything is working in Entra ID and also in on-premises.
You are facing some issues with groups memberships. New object which was created in forest doesn't have the group membership in on-premises as old object.
I think when the object is moved from one domain in on-prem to another domain, group memberships are not carried along with the user.
Usually with if you migrate users using ADMT tool it creates groups associated with the user being migrated accounts and maintains group membership in the target domain.
If the user group membership is intact in on-premises then there will not be any problems with group membership.
And if user is part of particular group in on-premises AD then Entra connect should sync the groups and membership without any issues provided groups are in Sync OU scope.
If you are seeing user not being part of any group in Entra ID then you will have to check in on-preimses if the group is syncing using Entra ID.
Let me know if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.