We have come across some cases when changes made in Active Directory are not recognized in ESM.
In order to resolved this issue:
On the ESM management servers, add the following registry key value and set it to 0.
DWORD Value: CacheS4UTickets
Right-click>>modify and make sure value is set to 0.
Please reference this Microsoft Technet article for more information: http://technet.microsoft.com/en-us/library/cc738673(v=ws.10).aspx