A customer has a number of DS 6.9 SP6 servers running Windows 2008 R2 in one domain, no longer being able to display domain group members for that domain via the 'Options > Security' UI.
They can see users and groups from that domain when browsing the domain during the action of adding domain objects to a local windows group on the server.
The DS Console displays domain group members from other domains that have trusts to this domain.
Nothing of relevance seems to be recorded in the event viewer logs, and the Kerberos MaxTokenSize is set to 0xffff already.
This problem was first noticed by the customer a couple of weeks ago.
Does anyone have an idea as to what is causing this issue?