Monitoring_user role does not work when assigned to AD-based role mapping

When assigning the monitoring_user role to a role mapping, where users assigned to the role are based on users from Active Directory, access is denied. The AD Users are also granted the Kibana_admin role.

Using a local Kibana user and assigning the same roles, it works fine.

Is there a bug when it comes to AD-integration or is it a feature?

How are you mapping the roles for AD users?
This is the method in the docs: https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-roles.html

I'm using the mapping tool in Kibana, assigning based on dn where cn=SamAccountName,dc=domainname,dc=tld

Access to spaces in Kibana is given the same way, which works