Is there a way to auto-sync to LDAP instead of having to click: "Reload authentication configuration" for every group membership change? Is this supposed to work in some other way automatically?
No way around that I am aware of. If you need to reload auth often there is a CLI option:
./splunk reload auth