Do the authentication test from the authentication realm to make sure there is no error in communication between WSA and the AD server, especially when fetching the authenticate groups.
Also make sure the 'redirect hostname' configure in the authentication global settings is using a single word hostname and resolving to the WSA IP address that handle data traffic. Since this redirect hostname will be used for authentication when using transparent mode(WCCP) to pass the authentication information from clients to WSA.
However would recommend to open a TAC case for the engineer to investigate in details.