Users that are no longer in the group in the "Allow Active Directory authentication only to certain group" configuration option of the active directory application should be deactivated, similar to users that are deactivated in LDAP.
This will probably require a new feature in the LDAP user cleanup extension.