As noted in the topic of this discussion I am encountering this issue.
The use case is restricting outbound smtps (tcp/587) to allow access only to smtp.office365.com. The customer environment is FMC-managed FTD 2140 with 6.4.0.4 software. DNS server groups are setup and the ACP is *mostly* working.
However, at unpredictable intervals, some printers are not able to communicate to the O365 servers. Analysis of Connection Events shows they are hitting a Block despite the destination address resolving to smtp.office365.com as verified on the FTD appliance itself.

This article seems to highlight the problem but doesn't suggest a work around:
https://community.cisco.com/t5/security-documents/using-hostnames-dns-in-access-lists-configuration-steps-caveats/ta-p/3123480#toc-hId--1214252331
I will open a TAC case when I get a chance but thought I'd try here first.