JaySimmons cheers for taking the time!
Was a great ride finding the cause.
GPO EXAMPLE (not working)
("SID")
or
"CONTOSO\GROUP OR USER"
WORKING EXAMPLE
SID
CONTOSO\GROUP OR USER
How to make customers more secure and happy:
That said, implementation of Windows LAPS, without compat modes needed on all Windows Servers (2019 or newer only), worked like a charm.
All passwords, if permitted, easily accessible in Active Directory Administrative Center (DSAC)
All they needed were 2 Group Policies, and 3 AD Groups (one for Domain Controllers, one for other servers, one for those that shall not receive LAPS for a reason, such as Citrix VAD etc., put in each GPO apply denied).
Except the glitch, documentation, troubleshooting guidance, PowerShell support, everything was top notch. KUDOS! Great product and enhancement over legacy LAPS.
Next stop: Windows LAPS for Intune.
Have heard different opinions about manageability.