This week I upgraded our two managers from 2.15 to 2.18. They upgraded normally without issues or errors. Afterwards I noticed that app stacks were not attaching for new logins. Thinking that it may be something with the 2.18 managers and the 2.15 agent I pushed a new clone out with the 2.18 agent and that didn't resolve the issue. We assign all stacks to security groups normally. Assigning them to my user account or computer object made them attach fine. Turning on the advanced setting option for "Disable Token AD query" also made them attach normally. This option was previously off in 2.15 and worked just fine. I would like to be able to turn that back off if someone has any ideas for what I might be missing.
Nothing immediately jumped out at me in the client side log or the server log. Some additional information is below -
ESXi 6.0 U3
Windows 10 1803 instant clones
Three domain forest, groups are in the top domain in the forest, user accounts in the groups are in the two child domains