How User AD Import Works with Resource Group Access

How User AD Import Works with Resource Group Access

We use AD import to import users into PMP on a schedule. When they are imported, they are given access to a resource group based on the AD group the user is in. (Example: Service Desk AD group gets access to Service Desk Resource Group)

1. If the user is removed from the AD group, the schedule runs and user is no longer in the AD group. Should the user remain in PMP and continue to have access to the Service Desk? I tested this and find that a user still has access to the group. 

2. How do I remove the user from having access to the service desk? I can edit user, "add user to multiple groups" and see the group here but it is greyed out. A window pops up saying "User is required to approve the access control of the resources" when I hover the mouse over the group. I cannot remove the user. 

3. Do I just need to delete the user? Seems dramatic.