Do you have a local user account and domain user account that shares the same short name? It was fixed some time ago for my situation of a local and LDAP account sharing the same short name. The version of DSM back then (7.0 in Aug 2021) started to prioritise the LDAP account when the short name was used, when it really should've checked if there was an absolute match in the local accounts and only then match to the LDAP account.
This was fixed and I've not seen something like it being raised since.
Of course, check that the domain user or its domain group has access to SMB Service.