Issue with AD username passed to the domain controller.

I recently upgraded some machines to 10.13.6 and now the AD accounts are passing a bad user ID to the domain controller. Instead up showing up as Domainusername it's Domain.netusername. Which would be fine, but the firewall rules are looking for Domain

The strangest part is that it's not happening to every user on the machine. If I create a new AD account on the machine the ad controller will see it as Domain. If I deleted the user that's having issues and have them create a new account on the machine they end up as again.

Both user accounts look the same in the directory editor, and the dsconfigad results are identical between a machine that's having issues and one that isn't.