Your comments

Yeah, I looked through the ldap structure using ldp in Windows and set the base DN to a Security group's CN, for example, if a security group's CN is AjentiAccess, the base DN string would look like: CN=AjentiAccess,OU=Ajenti,OU=Groups,OU=IT,DC=domain,DC=com

When I do that, the sync returns no errors, but it isn't able to find any children. However, if I start the base DN with an OU, it does seem to find all of the users in the OU, excluding the security group or its members.