Hi Nick, I upgraded my DC's to 2016 over the past week and then I linked Office 365 into our AD... I then noticed the problem, so I suspect the problem was the Office 365 integration and not the moving over the DC's. However after thinking through it logically, the user was being recognized but the security groups wasn't, plus after pointing the HAP+ server to a specific DC I was still experiencing the same issue, so my mind fell on the 2016 install... After checking this a little more, I noticed one of my legacy DC's (2012 R2) was still in my sites and services and my new DC's was attempting to replicate to and from it, I promptly removed this and done a fresh replication and bingo! The users were recognizing the security groups once more. A quick dns/host file fix on the HAP+ server and then fix the setup.aspx access rights again and my HAP+ is all happy again.
Thanks again for your messages