But in a way you're up to something:
This group ›staff‹ is only defined in Cloudron, not in NC.
Maybe user_ldap also fetches group assignments from Cloudron no matter if defined in NC, wheras ›OpenID connect user backend‹ only fetches those available in the app / in NC.
I'll try that.