Just a quick update about this. I found that if I changed the groups in the OUs to domain local instead of global, the login script works flawlessly for the whole company. I don't really get that since we use one domain name.