After logon with a local Admin account, we could see that he LDAP config had been wiped out during the upgrade process. Recreating this and everything sync’d up again nicely.
One gotha was using a admin account that was giving us some false results due to the account being ‘locked out’ in Zammad.
To the developers: It would be nice to ‘Account locked out’ message forwarded to the logon page rather than a generic “Check your credentials” followed by the CSRF Token failed message on an second attempt.