Adding group membership via app-groups does not replicate memberOf records to the Slave
If you maintain a user's group membership using the Groups menu or app-accounts > app-policy then no "memberOf" record for the user's dn is replicated from the Master to the Slave.
The same bug is being filed against app-central-management, app-ldap and app-openldap as I am not sure where it lies.