I struggled getting AD permissions to work for over a day and finally just gave up. Like you, I followed that guide but just ended up with broken access. If I restored the permissions from the Unraid side then it would completely ignore the AD permissions (users with read-only access could modify files.) I could get it somewhat working by granting ownership of the files to an AD account then recursively enabling inheritance to all folders & files. That fixed read-only but now other read-write users got denied access by the ownership even though they had the proper permissions. I also come from an enterprise IT background and setting up a basic SMB share with on Windows servers or other NAS devices like Synology, QNAP, or even Isilon has never been this frustrating. I ended up changing the SMB settings back to Workgroup and used the Credential Manager on all the clients to map to local Unraid accounts. It appears to be working but I would have preferred using AD accounts and groups to control access.
Overall I have been very happy with Unraid but I would love to see a focus on improving more security focused items. Reading through the forums while troubleshooting the AD permissions I found very little information on configuring AD and would constantly see replies for general SMB issues about how it's meant to be a home product or disabling security features to get it to work. Improvements like adding an MFA option is often met with resistance and comments like "just don't connect it to the internet." Yes, most users of the product are going to be fine with the out of the box setup, but I'm sure there are plenty of us who would like the simplicity of the array setup but would like things like better AD integration or MFA.