I don't think the answers really address the question so let me re-phrase it.
I am using an AD security group to provide access to a sharepoint document library.
The AD security group is synced; it's part of the AD sync.
I remove a member from the security group.
I wait 35 minutes.
I check the group online in the o365 admin center, and I confirm that the user is indeed gone from the security group.
But the user STILL has access to the Document Library. When I go to the doc library and use the "check permissions" button, and put in the username, and click check permissions, it says they STILL have access from the security group that I removed them over 35 minutes ago.
So I think the question is, after the security groups/users have been synced and are up-to-date on o365 (online) then how long before SharePoint actually recognizes that? I can tell you for sure it's over 1.5 hours. I've been testing it today. I also forced an "initial" AD sync via Powershell, so the 30 minute delay doesn't apply to my situation.
I'm 1.5 hours into this, and SharePoint has not recognized the updated security group membership yet, although the security group has shown accurate online for the entire time.