It seems when adding an agent to an agent group, it does not automatically inherit the agent group settings.
Instead you have to remove each property that you want inherited. This is very counter intuitive, and also a possible security and configuration risk.
The idea of groups, from my perspective, is to be able to configure and manage multiple agents as a whole. If I create a new agent, I now have to go through several more steps after adding the agent to a group to make sure all the settings are right and consistent with the other agents in the group.
Another issue with the current inheritance model is if a new property is added by an upgrade, i now have to remember to go back and change for each agent that is in a group its configuration or inheritance setting.
I do have a suggestion on how to implement. (it just an idea), add a flag to the ssoadm add-agent-to-grp command that forces the inheritance.