This is a regression from version 2.14 - some users aren't able to login: the AD log states that the user logged in successfully, but the acegisecurity log throws a false AccountExpiredException. Unfortunately I haven't figured out on what logic a user was regarded as expired, otherwise I would've provided more information.
Downgrading back to 2.14 eliminated the issue for all users that couldn't login.