The Umbrella Active Directory connector typically does not import built-in AD groups to Umbrella.
Starting 08-June-2020, if the Connector is doing a synchronization of the entire AD tree (if the C:\CiscoUmbrellaADGroups.dat file is not present on the Connector), the built-in groups Domain Users and Domain Computers will also be imported to Umbrella.
If the C:\CiscoUmbrellaADGroups.dat file is present on the Connector, only the groups specified in this file and sub-groups of these groups (except built-in groups) will be synchronized to Umbrella. There is no change to this behavior. Domain Users and Domain Computers groups, even if present in the file, will not be synchronized to Umbrella.
The list of built-in groups that are not imported to Umbrella is present here.