The apparent change in ad_gpo_access_control in sssd-1.13.2 in Fedora 22 broke my setup as well --- although for me it was a "permission denied" failure in the "account" PAM module which only occurred when logging in with xscreensaver (not when logging in at a virtual console).
Is this possibly an SSSD bug, or is it a broken AD setup? What's the best way to debug this type of problem?