Only a home user here, so I kept it simple for myself.I selected the Domain Admins under Authentication Containers in System:Access:Servers eq "OU=Domain Admins,DC=weust,DC=local" (without the quotes, since you can browse it).Perhaps use a AD Global Group instead of a box group?
I do have a user on the OPNsense box that is connected to my AD.But it's been so long I can't remember exactly how I did it.I'd have to create a new user in my AD and set that up in OPNsense to figure out how exactly I got it to work...
This isn't pfSense ;-)Maybe a dev can clarify, but I believe it's not yet possible atm.And check on IRC as well.